BindFlt DLL loaded by an unusual process
Detects the loading of bindfltapi.dll, bindflt.dll, or bindlink.dll DLL family that represents user-mode API surface of the Windows Bind Filter driver (bindflt.sys) by processes outside the known legitimate consumer set. The Bind Filter driver allows administrator-level callers to create transparent, application-invisible redirections from a virtual file system path to an arbitrary local or remote backing path. While legitimately used by WSL2, Windows Containers, Windows Sandbox, Hyper-V, and MSIX packaging, this capability has been weaponised in multiple public tools to perform EDR and AV evasion.
- Platform: Windows
- Severity: High
- MITRE Tactic: Defense Evasion
- MITRE Techniques: T1574