Untrusted DLL loaded from masqueraded Windows directory

Identifies trusted process executables loading unsigned or untrusted Dynamic Link Libraries (DLLs) from filesystem paths that masquerade as legitimate Windows system directories. Attackers frequently create lookalike directory structures to disguise malicious payloads as legitimate operating system components.

Volver a todas las reglas