DLL旁加载检测
原名:detecting-dll-sideloading-attacks
检测DLL侧加载和搜索顺序劫持(MITRE T1574),通过分析Sysmon事件ID 7的DLL加载事件,检查签名/哈希与已知良好版本,并使用CrowdStrike、MDE或SentinelOne等EDR工具标记路径异常。适用于调查EDR警报、狩猎APT持久化或处理DLL劫持事件。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-07
- TRACE 评分
- 3.4 / 5
内容概览
- When investigating potential DLL hijacking in enterprise environments - After EDR alerts on unsigned DLLs loaded by signed applications - When hunting for APT persistence using legitimate application wrappers - During incident response to identify trojanized applications - When threat intel indicates DLL sideloading campaigns targeting specific software - EDR with DLL load monitoring (CrowdStrike, MDE, SentinelOne) - Sysmon Event ID 7 (Image Loaded) with hash verification - Application whitelisting or DLL integrity monitoring - Software inventory of legitimate applications and expected DLL paths - Code signing verification capabilities 1. Identify Sideloading Targets : Research known vulnerable applications that load DLLs without full path qualification (LOLBAS, DLL-sideload databases). 2. Monitor DLL Load Events : Query Sysmon Event ID 7 for DLL loads where the DLL path differs from t…