Files
splunk-security_content/detections/endpoint/windows_unsigned_dll_side_loading.yml
T

81 lines
3.7 KiB
YAML

name: Windows Unsigned DLL Side-Loading
id: 5a83ce44-8e0f-4786-a775-8249a525c879
version: 11
date: '2025-05-02'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
data_source:
- Sysmon EventID 7
description:
The following analytic detects the creation of potentially malicious
unsigned DLLs in the c:\windows\system32 or c:\windows\syswow64 folders. It leverages
Sysmon EventCode 7 logs to identify unsigned DLLs with unavailable signatures loaded
in these critical directories. This activity is significant as it may indicate a
DLL hijacking attempt, a technique used by attackers to gain unauthorized access
and execute malicious code. If confirmed malicious, this could lead to privilege
escalation, allowing the attacker to gain elevated privileges and further compromise
the target system.
search:
'`sysmon` EventCode=7 Signed=false OriginalFileName = "-" SignatureStatus="unavailable"
ImageLoaded IN ("*:\\windows\\system32\\*", "*:\\windows\\syswow64\\*") | fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded
dest loaded_file loaded_file_path original_file_name process_exec process_guid process_hash
process_id process_name process_path service_dll_signature_exists service_dll_signature_verified
signature signature_id user_id vendor_product | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_unsigned_dll_side_loading_filter`'
how_to_implement:
To successfully implement this search, you need to be ingesting
logs with the process name and imageloaded executions from your endpoints. If you
are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives:
It is possible some Administrative utilities will load dismcore.dll
outside of normal system paths, filter as needed.
references:
- https://asec.ahnlab.com/en/17692/
- https://www.blackberry.com/us/en/solutions/endpoint-security/ransomware-protection/warzone#:~:text=Warzone%20RAT%20(AKA%20Ave%20Maria)%20is%20a%20remote%20access%20trojan,is%20as%20an%20information%20stealer.
drilldown_searches:
- name: View the detection results for - "$dest$"
search: '%original_detection_search% | search dest = "$dest$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
search:
'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: An unsigned dll module was loaded on $dest$
risk_objects:
- field: dest
type: system
score: 49
threat_objects: []
tags:
analytic_story:
- China-Nexus Threat Activity
- Derusbi
- Warzone RAT
- Salt Typhoon
- NjRAT
- Earth Alux
asset_type: Endpoint
mitre_attack_id:
- T1574.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/warzone_rat/unsigned_dll_loaded/loaded_unsigned_dll.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog