Untrusted DLL loaded from unusual directory

Identifies trusted, digitally signed executables loading unsigned or untrusted Dynamic Link Libraries (DLLs) from user-writable or otherwise uncommon filesystem locations. Adversaries frequently abuse these directories to stage malicious libraries that are subsequently loaded by legitimate applications, allowing arbitrary code to execute within the context of a trusted process while reducing the likelihood of detection.

Volver a todas las reglas