Files

100 KiB

1islibrarylibraryexcludesttpcomment
2TRUEaclui.dll*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
3TRUEaclui.dll*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
4TRUEacrodistdll.dll*\Program Files\Adobe\Acrobat *T1574.002https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
5TRUEacrodistdll.dll*\Acrobat\acrodistdll*T1574.002https://go.recordedfuture.com/hubfs/reports/cta-2022-1223.pdf
6TRUEactiveds.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
7TRUEactiveds.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
8TRUEadsldpc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
9TRUEadsldpc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
10TRUEaepic.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
11TRUEaepic.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
12TRUEapphelp.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
13TRUEapphelp.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
14TRUEapplicationframe.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
15TRUEapplicationframe.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
16TRUEappvpolicy.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
17TRUEappwiz.cpl*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
18TRUEappwiz.cpl*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
19TRUEappxalluserstore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
20TRUEappxalluserstore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
21TRUEappxdeploymentclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
22TRUEappxdeploymentclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
23TRUEarchiveint.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
24TRUEarchiveint.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
25TRUEashldres.dll*\Program Files\McAfee.com\VSO*T1574.002https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-rotten-tomato-campaign.pdf
26TRUEatl.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
27TRUEatl.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
28TRUEatltracetoolui.dll*\Program Files\Microsoft Visual Studio 11.0\Common7\Tools*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
29TRUEaudioses.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
30TRUEaudioses.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
31TRUEauditpolcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
32TRUEauditpolcore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
33TRUEauthfwcfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
34TRUEauthfwcfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
35TRUEauthz.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
36TRUEauthz.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
37TRUEavrt.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
38TRUEavrt.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
39TRUEbasicnetutils.dll*\Appdata\local\Temp\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
40TRUEbasicnetutils.dll*\Program Files\BAIDU\BAIDUPINYIN\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
41TRUEbatmeter.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
42TRUEbatmeter.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
43TRUEbcd.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
44TRUEbcd.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
45TRUEbcp47langs.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
46TRUEbcp47langs.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
47TRUEbcp47mrm.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
48TRUEbcp47mrm.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
49TRUEbcrypt.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
50TRUEbcrypt.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
51TRUEbderepair.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
52TRUEbootmenuux.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
53TRUEbootux.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
54TRUEcabinet.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
55TRUEcabinet.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
56TRUEcabview.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
57TRUEcabview.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
58TRUEcertcli.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
59TRUEcertcli.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
60TRUEcertenroll.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
61TRUEcertenroll.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
62TRUEcfgmgr32.dll*\Windows\System32\*T1574.002
63TRUEcfgmgr32.dll*\Windows\SysWOW64\*T1574.002
64TRUEchrome_frame_helper.dll*\Appdata\local\Google\Chrome\Application*T1574.002https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
65TRUEchrome_frame_helper.dll*\Program Files\Google\Chrome\Application*T1574.002https://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/
66TRUEciscosparklauncher.dll*\Appdata\local\CiscoSparkLauncher*T1574.002https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
67TRUEciscosparklauncher.dll*\AppData\Local\Programs\Cisco Spark\*T1574.002https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
68TRUEclassicexplorer32.dll*\Program Files\Classic Shell*T1574.002https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
69TRUEclassicexplorer32.dll*\Program Files\Open-Shell*T1574.002https://blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets
70TRUEcldapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
71TRUEcldapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
72TRUEclipc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
73TRUEclipc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
74TRUEclusapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
75TRUEclusapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
76TRUEcmpbk32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
77TRUEcmpbk32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
78TRUEcmutil.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
79TRUEcmutil.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
80TRUEcoloradapterclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
81TRUEcoloradapterclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
82TRUEcolorui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
83TRUEcolorui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
84TRUEcomdlg32.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
85TRUEcomdlg32.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
86TRUEcommfunc.dll*\Program Files\Lenovo\Communications Utility*T1574.002https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
87TRUEconfigmanager2.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
88TRUEconnect.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
89TRUEconnect.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
90TRUEcoredplus.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
91TRUEcoremessaging.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
92TRUEcoremessaging.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
93TRUEcoreuicomponents.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
94TRUEcoreuicomponents.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
95TRUEcredui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
96TRUEcredui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
97TRUEcryptbase.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
98TRUEcryptbase.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
99TRUEcryptdll.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
100TRUEcryptdll.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
101TRUEcryptsp.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
102TRUEcryptsp.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
103TRUEcryptui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
104TRUEcryptui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
105TRUEcryptxml.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
106TRUEcryptxml.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
107TRUEcscapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
108TRUEcscapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
109TRUEcscobj.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
110TRUEcscobj.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
111TRUEcscui.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
112TRUEcscui.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
113TRUEd2d1.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
114TRUEd2d1.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
115TRUEd3d10.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
116TRUEd3d10.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
117TRUEd3d10_1.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
118TRUEd3d10_1.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
119TRUEd3d10_1core.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
120TRUEd3d10_1core.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
121TRUEd3d10core.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
122TRUEd3d10core.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
123TRUEd3d10warp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
124TRUEd3d10warp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
125TRUEd3d11.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
126TRUEd3d11.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
127TRUEd3d12.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
128TRUEd3d12.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
129TRUEd3d9.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
130TRUEd3d9.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
131TRUEd3dcompiler_47.dll*\Program Files\windows kits\10\bin\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
132TRUEd3dcompiler_47.dll*\Program Files\windows kits\10\bin\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
133TRUEd3dcompiler_47.dll*\Program Files\windows kits\10\redist\d3d\x64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
134TRUEd3dcompiler_47.dll*\Program Files\windows kits\10\redist\d3d\x86*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
135TRUEd3dcompiler_47.dll*\Program Files\wireshark*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
136TRUEd3dcompiler_47.dll*\Program Files\cisco systems\cisco jabber*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
137TRUEd3dcompiler_47.dll*\Program Files\microsoft\edge\application\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
138TRUEd3dcompiler_47.dll*\Program Files\Google\Chrome\Application\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
139TRUEd3dcompiler_47.dll*\Appdata\local\microsoft\teams\stage*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
140TRUEd3dcompiler_47.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
141TRUEd3dcompiler_47.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
142TRUEd3dcompiler_47.dll*\Microsoft\Teams\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
143TRUEd3dx9_43.dll*\Windows\System32\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
144TRUEd3dx9_43.dll*\Windows\SysWOW64\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
145TRUEdataexchange.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
146TRUEdataexchange.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
147TRUEdavclnt.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
148TRUEdavclnt.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
149TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\arm*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
150TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\arm\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
151TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\arm64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
152TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\arm64\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
153TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\x64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
154TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\x64\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
155TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\x86*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
156TRUEdbgcore.dll*\Program Files\windows kits\10\debuggers\x86\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
157TRUEdbgcore.dll*\Program Files\microsoft office\root\office*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
158TRUEdbgcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
159TRUEdbgcore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
160TRUEdbgeng.dll*\Program Files\Windows Kits\*T1574.002https://twitter.com/mrexodia/status/1630320327967252483
161TRUEdbgeng.dll*\Program Files\Windows Kits\*T1574.002https://twitter.com/mrexodia/status/1630320327967252483
162TRUEdbgeng.dll*\Program Files\Windows Kits\*T1574.002https://twitter.com/mrexodia/status/1630320327967252483
163TRUEdbgeng.dll*\Program Files\Windows Kits\*T1574.002https://twitter.com/mrexodia/status/1630320327967252483
164TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\arm*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
165TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\arm\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
166TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\arm64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
167TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\arm64\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
168TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\x64*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
169TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\x64\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
170TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\x86*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
171TRUEdbghelp.dll*\Program Files\windows kits\10\debuggers\x86\srcsrv*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
172TRUEdbghelp.dll*\Program Files\cisco systems\cisco jabber*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
173TRUEdbghelp.dll*\Program Files\microsoft office\root\office*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
174TRUEdbghelp.dll*\Program Files\microsoft office\root\vfs\programfilesx86\microsoft analysis services\as oledb\140*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
175TRUEdbghelp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
176TRUEdbghelp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
177TRUEdbgmodel.dll*\Windows\System32\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
178TRUEdbgmodel.dll*\Windows\SysWOW64\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
179TRUEdbgmodel.dll*\Program Files\Windows Kits\10\Debuggers\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
180TRUEdcntel.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
181TRUEdcomp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
182TRUEdcomp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
183TRUEdefragproxy.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
184TRUEdefragproxy.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
185TRUEdesktopshellext.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
186TRUEdesktopshellext.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
187TRUEdeviceassociation.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
188TRUEdeviceassociation.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
189TRUEdevicecredential.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
190TRUEdevicecredential.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
191TRUEdevicepairing.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
192TRUEdevicepairing.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
193TRUEdevobj.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
194TRUEdevobj.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
195TRUEdevrtl.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
196TRUEdevrtl.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
197TRUEdhcpcmonitor.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
198TRUEdhcpcmonitor.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
199TRUEdhcpcsvc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
200TRUEdhcpcsvc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
201TRUEdhcpcsvc6.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
202TRUEdhcpcsvc6.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
203TRUEdirectmanipulation.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
204TRUEdirectmanipulation.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
205TRUEdismapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
206TRUEdismapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
207TRUEdismcore.dll*\Windows\System32\dism*T1574.001https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
208TRUEdismcore.dll*\Windows\SysWOW64\dism*T1574.001https://cofense.com/exploiting-unpatched-vulnerability-ave_maria-malware-not-full-grace/
209TRUEdmcfgutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
210TRUEdmcfgutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
211TRUEdmcmnutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
212TRUEdmcmnutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
213TRUEdmcommandlineutils.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
214TRUEdmcommandlineutils.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
215TRUEdmenrollengine.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
216TRUEdmenrollengine.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
217TRUEdmenterprisediagnostics.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
218TRUEdmiso8601utils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
219TRUEdmiso8601utils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
220TRUEdmoleaututils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
221TRUEdmoleaututils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
222TRUEdmprocessxmlfiltered.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
223TRUEdmprocessxmlfiltered.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
224TRUEdmpushproxy.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
225TRUEdmpushproxy.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
226TRUEdmxmlhelputils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
227TRUEdmxmlhelputils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
228TRUEdnsapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
229TRUEdnsapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
230TRUEdot3api.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
231TRUEdot3api.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
232TRUEdot3cfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
233TRUEdot3cfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
234TRUEdpx.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
235TRUEdpx.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
236TRUEdrprov.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
237TRUEdrprov.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
238TRUEdrvstore.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
239TRUEdrvstore.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
240TRUEdsclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
241TRUEdsclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
242TRUEdsparse.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
243TRUEdsparse.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
244TRUEdsprop.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
245TRUEdsprop.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
246TRUEdsreg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
247TRUEdsreg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
248TRUEdsrole.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
249TRUEdsrole.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
250TRUEdui70.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
251TRUEdui70.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
252TRUEduser.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
253TRUEduser.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
254TRUEdusmapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
255TRUEdusmapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
256TRUEdwmapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
257TRUEdwmapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
258TRUEdwmcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
259TRUEdwrite.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
260TRUEdwrite.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
261TRUEdxcore.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
262TRUEdxcore.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
263TRUEdxgi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
264TRUEdxgi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
265TRUEdxva2.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
266TRUEdxva2.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
267TRUEdynamoapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
268TRUEeappcfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
269TRUEeappcfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
270TRUEeappprxy.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
271TRUEeappprxy.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
272TRUEedgeiso.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
273TRUEedgeiso.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
274TRUEedputil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
275TRUEedputil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
276TRUEefsadu.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
277TRUEefsadu.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
278TRUEefsutil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
279TRUEefsutil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
280TRUEesent.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
281TRUEesent.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
282TRUEexecmodelproxy.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
283TRUEexecmodelproxy.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
284TRUEexplorerframe.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
285TRUEexplorerframe.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
286TRUEfacesdk.dll*\Program Files\luxand\facesdk\bin\win64*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
287TRUEfastprox.dll*\Windows\System32\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
288TRUEfastprox.dll*\Windows\SysWOW64\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
289TRUEfaultrep.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
290TRUEfaultrep.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
291TRUEfddevquery.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
292TRUEfddevquery.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
293TRUEfeclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
294TRUEfeclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
295TRUEfhcfg.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
296TRUEfhcfg.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
297TRUEfhsvcctl.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
298TRUEfirewallapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
299TRUEfirewallapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
300TRUEflightsettings.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
301TRUEflightsettings.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
302TRUEfltlib.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
303TRUEfltlib.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
304TRUEformdll.dll*\Program Files\Common Files\Microsoft Shared\NoteSync Forms*T1574.002https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1
305TRUEframedynos.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
306TRUEframedynos.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
307TRUEfveapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
308TRUEfveapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
309TRUEfveskybackup.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
310TRUEfvewiz.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
311TRUEfwbase.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
312TRUEfwbase.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
313TRUEfwcfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
314TRUEfwcfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
315TRUEfwpolicyiomgr.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
316TRUEfwpolicyiomgr.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
317TRUEfwpuclnt.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
318TRUEfwpuclnt.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
319TRUEfxsapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
320TRUEfxsapi.dll*\Windows\System32\driverstore\filerepository\prnms002.inf_*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
321TRUEfxsapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
322TRUEfxsst.dll*\Windows\System32\*T1574.001https://www.fireeye.com/blog/threat-research/2011/06/fxsst.html/
323TRUEfxstiff.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
324TRUEfxstiff.dll*\Windows\System32\driverstore\filerepository\prnms002.inf_*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
325TRUEgetuname.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
326TRUEgetuname.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
327TRUEgflagsui.dll*\Program Files\Windows Kits\10\Debuggers\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
328TRUEglib-2.0.dll*\Program Files\VMware\VMware Tools*T1574.002https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
329TRUEglib-2.0.dll*\Program Files\VMware\VMware Workstation*T1574.002https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
330TRUEglib-2.0.dll*\Program Files\VMware\VMware Player*T1574.002https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
331TRUEgpapi.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
332TRUEgpapi.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
333TRUEhha.dll*\Windows\System32\*T1574.002https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
334TRUEhha.dll*\Windows\SysWOW64\*T1574.002https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
335TRUEhha.dll*\Program Files\HTML Help Workshop*T1574.002https://blog.trendmicro.com/trendlabs-security-intelligence/new-wave-of-plugx-targets-legitimate-apps/
336TRUEhid.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
337TRUEhid.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
338TRUEhnetmon.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
339TRUEhnetmon.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
340TRUEhpcustpartui.dll*\Program Files\HP*T1574.002https://www.trellix.com/en-us/about/newsroom/stories/research/operation-harvest-a-deep-dive-into-a-long-term-campaign.html
341TRUEhpqhvsei.dll*\Program Files\HP*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
342TRUEhttpapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
343TRUEhttpapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
344TRUEicmp.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
345TRUEicmp.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
346TRUEidstore.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
347TRUEidstore.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
348TRUEieadvpack.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
349TRUEieadvpack.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
350TRUEiedkcs32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
351TRUEiedkcs32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
352TRUEiernonce.dll*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
353TRUEiernonce.dll*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2023/12/26/1-little-known-secret-of-runonce-exe-32-bit/
354TRUEiertutil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
355TRUEiertutil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
356TRUEifmon.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
357TRUEifmon.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
358TRUEifsutil.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
359TRUEifsutil.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
360TRUEinproclogger.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
361TRUEiphlpapi.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
362TRUEiphlpapi.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
363TRUEiri.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
364TRUEiri.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
365TRUEiscsidsc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
366TRUEiscsidsc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
367TRUEiscsiexe.dll*\Windows\System32\*T1574.001https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
368TRUEiscsiexe.dll*\Windows\SysWOW64\*T1574.001https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC
369TRUEiscsium.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
370TRUEiscsium.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
371TRUEisv.exe_rsaenh.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
372TRUEisv.exe_rsaenh.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
373TRUEiumbase.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
374TRUEiumsdk.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
375TRUEiviewers.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
376TRUEiviewers.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
377TRUEiviewers.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
378TRUEiviewers.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
379TRUEjoinutil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
380TRUEjoinutil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
381TRUEkdstub.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
382TRUEksuser.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
383TRUEksuser.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
384TRUEktmw32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
385TRUEktmw32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
386TRUEldvpocx.ocx*\Program Files\Symantec_Client_Security\Symantec AntiVirus*T1574.002https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
387TRUEldvpocx.ocx*\Program Files\Symantec AntiVirus*T1574.002https://www.secureworks.com/research/a-peek-into-bronze-unions-toolbox
388TRUElibcares-2.dll*\git\mingw64\*T1574.002https://www.trellix.com/en-au/blogs/research/hiding-in-plain-sight-multi-actor-ahost-exe-attacks/
389TRUElibvlc.dll*\Program Files\VideoLAN\VLC*T1574.002https://news.sophos.com/en-us/2022/11/03/family-tree-dll-sideloading-cases-may-be-related/
390TRUElicensemanagerapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
391TRUElicensemanagerapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
392TRUElicensingdiagspp.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
393TRUElicensingdiagspp.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
394TRUElinkinfo.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
395TRUElinkinfo.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
396TRUElmiguardiandll.dll*\Program Files\LogMeIn*T1574.002https://twitter.com/StopMalvertisin/status/1610961056163311619
397TRUElmiguardiandll.dll*\Program Files\LogMeIn\x86*T1574.002https://twitter.com/StopMalvertisin/status/1610961056163311619
398TRUElmiguardiandll.dll*\Program Files\LogMeIn\x64*T1574.002https://twitter.com/StopMalvertisin/status/1610961056163311619
399TRUEloadperf.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
400TRUEloadperf.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
401TRUElockdown.dll*\Program Files\McAfee\VirusScan Enterprise*T1574.002https://twitter.com/thepacketrat/status/1520878930449817600
402TRUElockhostingframework.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
403TRUElog.dll*\Program Files\Bitdefender Antivirus Free*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
404TRUElogoncli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
405TRUElogoncli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
406TRUElogoncontroller.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
407TRUElogoncontroller.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
408TRUElpksetupproxyserv.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
409TRUElpksetupproxyserv.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
410TRUElrwizdll.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
411TRUEmagnification.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
412TRUEmagnification.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
413TRUEmaintenanceui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
414TRUEmapistub.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
415TRUEmapistub.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
416TRUEmbaexmlparser.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
417TRUEmdmdiagnostics.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
418TRUEmfc42u.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
419TRUEmfc42u.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
420TRUEmfcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
421TRUEmfcore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
422TRUEmfplat.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
423TRUEmfplat.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
424TRUEmi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
425TRUEmi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
426TRUEmidimap.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
427TRUEmidimap.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
428TRUEmintdh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
429TRUEmiutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
430TRUEmiutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
431TRUEmlang.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
432TRUEmlang.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
433TRUEmmdevapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
434TRUEmmdevapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
435TRUEmobilenetworking.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
436TRUEmobilenetworking.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
437TRUEmozglue.dll*\Program Files\SeaMonkey*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
438TRUEmozglue.dll*\Program Files\Mozilla Firefox*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
439TRUEmozglue.dll*\Program Files\Mozilla Thunderbird*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
440TRUEmozglue.dll*\AppData\Local\Mozilla Firefox\*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
441TRUEmpclient.dll*\Program Files\Windows Defender*T1574.002https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
442TRUEmpclient.dll*\ProgramData\Microsoft\Windows Defender\Platform\*T1574.002https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
443TRUEmpr.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
444TRUEmpr.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
445TRUEmprapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
446TRUEmprapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
447TRUEmpsvc.dll*\Program Files\Windows Defender\*T1574.002https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
448TRUEmpsvc.dll*\ProgramData\Microsoft\Windows Defender\Platform\*T1574.002https://www.mcafee.com/blogs/other-blogs/mcafee-labs/revil-ransomware-uses-dll-sideloading/
449TRUEmrmcorer.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
450TRUEmrmcorer.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
451TRUEmsacm32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
452TRUEmsacm32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
453TRUEmscms.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
454TRUEmscms.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
455TRUEmscoree.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
456TRUEmscoree.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
457TRUEmscorsvc.dll*\Windows\Microsoft.NET\Framework\v*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
458TRUEmscorsvc.dll*\Windows\Microsoft.NET\Framework64\v*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
459TRUEmsctf.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
460TRUEmsctf.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
461TRUEmsctfmonitor.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
462TRUEmsctfmonitor.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
463TRUEmsdrm.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
464TRUEmsdrm.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
465TRUEmsdtctm.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
466TRUEmsftedit.dll*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
467TRUEmsftedit.dll*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
468TRUEmsi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
469TRUEmsi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
470TRUEmsiso.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
471TRUEmsiso.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
472TRUEmsutb.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
473TRUEmsutb.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
474TRUEmsvcp110_win.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
475TRUEmsvcp110_win.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
476TRUEmsvcr100.dll*\Windows\System32\*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
477TRUEmsvcr100.dll*\Windows\SysWOW64\*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
478TRUEmswb7.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
479TRUEmswb7.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
480TRUEmswsock.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
481TRUEmswsock.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
482TRUEmsxml3.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
483TRUEmsxml3.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
484TRUEmtxclu.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
485TRUEmtxclu.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
486TRUEnapinsp.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
487TRUEnapinsp.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
488TRUEncrypt.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
489TRUEncrypt.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
490TRUEndfapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
491TRUEndfapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
492TRUEnetapi32.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
493TRUEnetapi32.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
494TRUEnetid.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
495TRUEnetid.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
496TRUEnetiohlp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
497TRUEnetiohlp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
498TRUEnetjoin.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
499TRUEnetjoin.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
500TRUEnetplwiz.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
501TRUEnetplwiz.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
502TRUEnetprofm.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
503TRUEnetprofm.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
504TRUEnetprovfw.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
505TRUEnetprovfw.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
506TRUEnetsetupapi.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
507TRUEnetsetupapi.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
508TRUEnetshell.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
509TRUEnetshell.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
510TRUEnettrace.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
511TRUEnetutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
512TRUEnetutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
513TRUEnetworkexplorer.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
514TRUEnetworkexplorer.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
515TRUEnewdev.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
516TRUEnewdev.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
517TRUEninput.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
518TRUEninput.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
519TRUEnlaapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
520TRUEnlaapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
521TRUEnlansp_c.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
522TRUEnlansp_c.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
523TRUEnpmproxy.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
524TRUEnpmproxy.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
525TRUEnshhttp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
526TRUEnshhttp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
527TRUEnshipsec.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
528TRUEnshipsec.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
529TRUEnshwfp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
530TRUEnshwfp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
531TRUEntdsapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
532TRUEntdsapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
533TRUEntlanman.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
534TRUEntlanman.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
535TRUEntlmshared.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
536TRUEntlmshared.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
537TRUEntmarta.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
538TRUEntmarta.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
539TRUEntshrui.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
540TRUEntshrui.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
541TRUEnvsmartmax.dll*\Program Files\NVIDIA Corporation\Display*T1574.002https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos
542TRUEoleacc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
543TRUEoleacc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
544TRUEomadmapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
545TRUEomadmapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
546TRUEonex.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
547TRUEonex.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
548TRUEopcservices.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
549TRUEopcservices.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
550TRUEopera_elf.dll*\Appdata\local\programs\opera\*T1574.002https://twitter.com/ShitSecure/status/1566127363389329412
551TRUEosbaseln.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
552TRUEosbaseln.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
553TRUEosksupport.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
554TRUEosuninst.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
555TRUEosuninst.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
556TRUEoutllib.dll*\Program Files\Microsoft Office\OFFICE*T1574.002https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
557TRUEoutllib.dll*\Program Files\Microsoft Office\Root\OFFICE*T1574.002https://medium.com/insomniacs/analysis-walkthrough-fun-clientrun-part-1-b2509344ebe6
558TRUEp2p.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
559TRUEp2p.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
560TRUEp2pnetsh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
561TRUEp2pnetsh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
562TRUEp9np.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
563TRUEp9np.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
564TRUEpcaui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
565TRUEpcaui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
566TRUEpdh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
567TRUEpdh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
568TRUEpeerdistsh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
569TRUEpeerdistsh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
570TRUEpkeyhelper.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
571TRUEpla.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
572TRUEpla.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
573TRUEplaysndsrv.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
574TRUEplaysndsrv.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
575TRUEpnrpnsp.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
576TRUEpnrpnsp.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
577TRUEpolicymanager.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
578TRUEpolicymanager.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
579TRUEpolstore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
580TRUEpolstore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
581TRUEpowrprof.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
582TRUEpowrprof.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
583TRUEprintui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
584TRUEprintui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
585TRUEprntvpt.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
586TRUEprntvpt.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
587TRUEprofapi.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
588TRUEprofapi.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
589TRUEpropsys.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
590TRUEpropsys.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
591TRUEproximitycommon.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
592TRUEproximitycommon.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
593TRUEproximityservicepal.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
594TRUEprvdmofcomp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
595TRUEprvdmofcomp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
596TRUEpuiapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
597TRUEpuiapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
598TRUEpython39.dll*\Program Files\Python39*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
599TRUEpython39.dll*\Appdata\local\Temp\*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
600TRUEpython39.dll*\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\CommonExtensions\Microsoft\VC\SecurityIssueAnalysis\python*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
601TRUEpython39.dll*\Users\anaconda3*T1574.002https://twitter.com/SBousseaden/status/1530595156055011330
602TRUEqrt.dll*\Program Files\F-Secure\Anti-Virus*T1574.002https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/
603TRUEradcui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
604TRUEradcui.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
605TRUErasapi32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
606TRUErasapi32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
607TRUErasdlg.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
608TRUErasdlg.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
609TRUErasgcw.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
610TRUErasgcw.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
611TRUErasman.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
612TRUErasman.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
613TRUErasmontr.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
614TRUErasmontr.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
615TRUErastls.dll*\Program Files\Symantec\Network Connected Devices Auto Setup*T1574.002https://st.drweb.com/static/new-www/news/2020/october/Study_of_the_ShadowPad_APT_backdoor_and_its_relation_to_PlugX_en.pdf
616TRUErcdll.dll*\Program Files\Windows Kits\10\bin\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
617TRUEreagent.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
618TRUEreagent.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
619TRUEregapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
620TRUEregapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
621TRUEreseteng.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
622TRUEresetengine.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
623TRUEresutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
624TRUEresutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
625TRUErjvplatform.dll*\Windows\System32\SystemResetPlatform*T1574.002https://twitter.com/0gtweet/status/1666716511988330499
626TRUErjvplatform.dll*\Windows\SysWOW64\SystemResetPlatform*T1574.002https://twitter.com/0gtweet/status/1666716511988330499
627TRUErmclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
628TRUErmclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
629TRUErpcnsh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
630TRUErpcnsh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
631TRUErsaenh.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
632TRUErsaenh.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
633TRUErtutils.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
634TRUErtutils.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
635TRUErtworkq.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
636TRUErtworkq.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
637TRUErzlog4cpp_logger.dll*\Appdata\local\razer\InGameEngine\cache\RzFpsApplet*T1574.002https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia
638TRUEsafestore32.dll*\Program Files\Sophos\Sophos Anti-Virus*T1574.002https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf
639TRUEsamcli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
640TRUEsamcli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
641TRUEsamlib.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
642TRUEsamlib.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
643TRUEsapi_onecore.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
644TRUEsapi_onecore.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
645TRUEsas.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
646TRUEsas.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
647TRUEscansetting.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
648TRUEscansetting.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
649TRUEscecli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
650TRUEscecli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
651TRUEschedcli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
652TRUEschedcli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
653TRUEsecur32.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
654TRUEsecur32.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
655TRUEsecurity.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
656TRUEsecurity.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
657TRUEsensapi.dll*\Windows\System32\*T1574.002https://twitter.com/AndrewOliveau/status/1682185200862625792
658TRUEsensapi.dll*\Windows\SysWOW64\*T1574.002https://twitter.com/AndrewOliveau/status/1682185200862625792
659TRUEshell32.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
660TRUEshell32.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
661TRUEshfolder.dll*\Windows\System32\*T1574.002https://twitter.com/dissectmalware/status/978017957480628226
662TRUEshfolder.dll*\Windows\SysWOW64\*T1574.002https://twitter.com/dissectmalware/status/978017957480628226
663TRUEsiteadv.dll*\Program Files\SiteAdvisor\*T1574.002https://www.nortonlifelock.com/sites/default/files/2021-10/OPERATION%20EXORCIST%20White%20Paper.pdf
664TRUEslc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
665TRUEslc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
666TRUEsmadhook32c.dll*\Program Files\Smadav*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
667TRUEsnmpapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
668TRUEsnmpapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
669TRUEspectrumsyncclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
670TRUEspp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
671TRUEspp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
672TRUEsppc.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
673TRUEsppc.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
674TRUEsppcext.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
675TRUEsppcext.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
676TRUEsrclient.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
677TRUEsrclient.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
678TRUEsrcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
679TRUEsrmtrace.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
680TRUEsrmtrace.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
681TRUEsrpapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
682TRUEsrpapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
683TRUEsrvcli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
684TRUEsrvcli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
685TRUEssp.exe_rsaenh.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
686TRUEssp.exe_rsaenh.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
687TRUEssp_isv.exe_rsaenh.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
688TRUEssp_isv.exe_rsaenh.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
689TRUEsspicli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
690TRUEsspicli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
691TRUEssshim.dll*\Windows\System32\*T1574.002https://twitter.com/0gtweet/status/1363107343018385410
692TRUEssshim.dll*\Windows\SysWOW64\*T1574.002https://twitter.com/0gtweet/status/1363107343018385410
693TRUEstaterepository.core.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
694TRUEstaterepository.core.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
695TRUEstructuredquery.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
696TRUEstructuredquery.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
697TRUEsxshared.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
698TRUEsxshared.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
699TRUEsymsrv.dll*\Program Files\Windows Kits\10\Debuggers\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
700TRUEsystemsettingsthresholdadminflowui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
701TRUEtapi32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
702TRUEtapi32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
703TRUEtbs.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
704TRUEtbs.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
705TRUEtdh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
706TRUEtdh.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
707TRUEtextshaping.dll*\Windows\System32\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
708TRUEtextshaping.dll*\Windows\SysWOW64\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
709TRUEtimesync.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
710TRUEtmdbglog.dll*\Program Files\Trend Micro\Titanium*T1574.002https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/space-pirates-tools-and-connections/
711TRUEtosbtkbd.dll*\Program Files\Toshiba\Bluetooth Toshiba Stack*T1574.002https://www.secureworks.com/research/shadowpad-malware-analysis
712TRUEtpmcoreprovisioning.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
713TRUEtpmcoreprovisioning.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
714TRUEtquery.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
715TRUEtquery.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
716TRUEtsworkspace.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
717TRUEtsworkspace.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
718TRUEttdrecord.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
719TRUEttdrecord.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
720TRUEtwext.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
721TRUEtwext.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
722TRUEtwinapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
723TRUEtwinapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/save-the-environment-variables
724TRUEtwinui.appcore.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
725TRUEtwinui.appcore.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
726TRUEuianimation.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
727TRUEuianimation.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
728TRUEuiautomationcore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
729TRUEuiautomationcore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
730TRUEuireng.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
731TRUEuireng.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
732TRUEuiribbon.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
733TRUEuiribbon.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
734TRUEumpdc.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
735TRUEumpdc.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
736TRUEunattend.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
737TRUEunityplayer.dll*\Appdata\local\Temp\*T1574.002https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/
738TRUEupdatepolicy.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
739TRUEupdatepolicy.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
740TRUEupshared.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
741TRUEurlmon.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
742TRUEurlmon.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
743TRUEuserenv.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
744TRUEuserenv.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
745TRUEutildll.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
746TRUEutildll.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
747TRUEuxinit.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
748TRUEuxinit.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
749TRUEuxtheme.dll*\Windows\System32\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
750TRUEuxtheme.dll*\Windows\SysWOW64\*T1574.001https://wietze.github.io/blog/hijacking-dlls-in-windows
751TRUEvaultcli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
752TRUEvaultcli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
753TRUEvdsutil.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
754TRUEvdsutil.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
755TRUEvender.dll*\Program Files\ASUS\GPU TweakII*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
756TRUEvender.dll*\Program Files\ASUS\VGA COM\*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
757TRUEversion.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
758TRUEversion.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
759TRUEvftrace.dll*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x32*T1574.002https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
760TRUEvftrace.dll*\Program Files\CyberArk\Endpoint Privilege Manager\Agent\x64*T1574.002https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
761TRUEvftrace.dll*\Program Files\CyberArk\Endpoint Privilege Manager\Agent*T1574.002https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/budworm-espionage-us-state?web_view=true
762TRUEvirtdisk.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
763TRUEvirtdisk.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
764TRUEvivaldi_elf.dll*\Appdata\local\Vivaldi\Application*T1574.002https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
765TRUEvivaldi_elf.dll*\Appdata\local\Vivaldi\Application\*T1574.002https://securityintelligence.com/posts/vizom-malware-targets-brazilian-bank-customers-remote-overlay/
766TRUEvntfxf32.dll*\Program Files\Venta\VentaFax & Voice*T1574.002https://decoded.avast.io/threatintel/apt-treasure-trove-avast-suspects-chinese-apt-group-mustang-panda-is-collecting-data-from-burmese-government-agencies-and-opposition-groups/
767TRUEvsodscpl.dll*\Program Files\McAfee\VirusScan Enterprise*T1574.002https://eiploader.wordpress.com/2011/03/28/digitally-signed-malware-without-stealing-certificates/
768TRUEvssapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
769TRUEvssapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
770TRUEvsstrace.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
771TRUEvsstrace.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
772TRUEwbemprox.dll*\Windows\System32\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
773TRUEwbemprox.dll*\Windows\SysWOW64\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
774TRUEwbemsvc.dll*\Windows\System32\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
775TRUEwbemsvc.dll*\Windows\SysWOW64\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
776TRUEwcmapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
777TRUEwcmapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
778TRUEwcnnetsh.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
779TRUEwdi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
780TRUEwdi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
781TRUEwdscore.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
782TRUEwdscore.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
783TRUEwebservices.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
784TRUEwebservices.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
785TRUEwecapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
786TRUEwecapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
787TRUEwer.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
788TRUEwer.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
789TRUEwevtapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
790TRUEwevtapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
791TRUEwhhelper.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
792TRUEwhhelper.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
793TRUEwimgapi.dll*\Windows\System32\*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
794TRUEwimgapi.dll*\Windows\SysWOW64\*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
795TRUEwimgapi.dll*\Program Files\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\arm64\DISM*T1574.002https://www.hexacorn.com/blog/2015/02/23/beyond-good-ol-run-key-part-28/
796TRUEwinbio.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
797TRUEwinbio.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
798TRUEwinbrand.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
799TRUEwinbrand.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
800TRUEwindows.storage.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
801TRUEwindows.storage.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
802TRUEwindows.storage.search.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
803TRUEwindows.storage.search.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
804TRUEwindows.ui.immersive.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
805TRUEwindows.ui.immersive.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
806TRUEwindowscodecs.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
807TRUEwindowscodecs.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
808TRUEwindowscodecsext.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
809TRUEwindowscodecsext.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
810TRUEwindowsperformancerecordercontrol.dll*\Program Files\windows kits\10\windows performance toolkit*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
811TRUEwindowsperformancerecordercontrol.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
812TRUEwindowsperformancerecordercontrol.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
813TRUEwindowsperformancerecorderui.dll*\Program Files\Windows Kits\10\Windows Performance Toolkit*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
814TRUEwindowsudk.shellcommon.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
815TRUEwindowsudk.shellcommon.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
816TRUEwinhttp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
817TRUEwinhttp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
818TRUEwininet.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
819TRUEwininet.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
820TRUEwinipsec.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
821TRUEwinipsec.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
822TRUEwinmde.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
823TRUEwinmm.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
824TRUEwinmm.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
825TRUEwinnsi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
826TRUEwinnsi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
827TRUEwinrnr.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
828TRUEwinrnr.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
829TRUEwinscard.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
830TRUEwinscard.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
831TRUEwinsqlite3.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
832TRUEwinsqlite3.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
833TRUEwinsta.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
834TRUEwinsta.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
835TRUEwinsync.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
836TRUEwinsync.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
837TRUEwinutils.dll*\Program Files\Palo Alto Networks\Traps*T1574.002https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/
838TRUEwkscli.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
839TRUEwkscli.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
840TRUEwlanapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
841TRUEwlanapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
842TRUEwlancfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
843TRUEwlancfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
844TRUEwldp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
845TRUEwldp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
846TRUEwlidprov.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
847TRUEwlidprov.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
848TRUEwmiclnt.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
849TRUEwmiclnt.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
850TRUEwmidcom.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
851TRUEwmidcom.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
852TRUEwmiutils.dll*\Windows\System32\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
853TRUEwmiutils.dll*\Windows\SysWOW64\wbem*T1574.007https://wietze.github.io/blog/save-the-environment-variables
854TRUEwmpdui.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
855TRUEwmsgapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
856TRUEwmsgapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
857TRUEwofutil.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
858TRUEwofutil.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
859TRUEwpdshext.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
860TRUEwpdshext.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
861TRUEwsc.dll*\Program Files\AVAST Software\Avast*T1574.001https://github.com/netero1010/Vulnerability-Disclosure/tree/main/CVE-2022-AVAST2
862TRUEwscapi.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
863TRUEwscapi.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
864TRUEwsdapi.dll*\Windows\System32\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
865TRUEwsdapi.dll*\Windows\SysWOW64\*T1574.002https://globetech.biz/index.php/2023/05/19/evading-edr-by-dll-sideloading-in-csharp/
866TRUEwshbth.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
867TRUEwshbth.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
868TRUEwshelper.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
869TRUEwshelper.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
870TRUEwsmsvc.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
871TRUEwsmsvc.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
872TRUEwtsapi32.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
873TRUEwtsapi32.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
874TRUEwwancfg.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
875TRUEwwancfg.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
876TRUEwwapi.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
877TRUEwwapi.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
878TRUExmllite.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
879TRUExmllite.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
880TRUExolehlp.dll*\Windows\System32\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
881TRUExolehlp.dll*\Windows\SysWOW64\*T1574.002https://wietze.github.io/blog/hijacking-dlls-in-windows
882TRUExpsservices.dll*\Windows\System32\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
883TRUExpsservices.dll*\Windows\SysWOW64\*T1574.002https://securityintelligence.com/posts/windows-features-dll-sideloading/
884TRUExwizards.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
885TRUExwizards.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
886TRUExwtpw32.dll*\Windows\System32\*T1574.007https://wietze.github.io/blog/save-the-environment-variables
887TRUExwtpw32.dll*\Windows\SysWOW64\*T1574.007https://wietze.github.io/blog/save-the-environment-variables