DLL旁加载检测

原名:detecting-dll-sideloading-attacks

检测DLL侧加载和搜索顺序劫持(MITRE T1574),通过分析Sysmon事件ID 7的DLL加载事件,检查签名/哈希与已知良好版本,并使用CrowdStrike、MDE或SentinelOne等EDR工具标记路径异常。适用于调查EDR警报、狩猎APT持久化或处理DLL劫持事件。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-09-07
TRACE 评分
3.4 / 5

内容概览

- When investigating potential DLL hijacking in enterprise environments - After EDR alerts on unsigned DLLs loaded by signed applications - When hunting for APT persistence using legitimate application wrappers - During incident response to identify trojanized applications - When threat intel indicates DLL sideloading campaigns targeting specific software - EDR with DLL load monitoring (CrowdStrike, MDE, SentinelOne) - Sysmon Event ID 7 (Image Loaded) with hash verification - Application whitelisting or DLL integrity monitoring - Software inventory of legitimate applications and expected DLL paths - Code signing verification capabilities 1. Identify Sideloading Targets : Research known vulnerable applications that load DLLs without full path qualification (LOLBAS, DLL-sideload databases). 2. Monitor DLL Load Events : Query Sysmon Event ID 7 for DLL loads where the DLL path differs from t…

查看 SKILL 详情