DLL loaded via APC queue
Identifies loading of a DLL with a callstack originating from the thread alertable state that led to the execution of an APC routine. This may be indicative of sleep obfuscation or process injection attempt.
- Platform: Windows
- Severity: High
- MITRE Tactic: Defense Evasion
- MITRE Techniques: T1055