DLL loading of a file transferred over SMB

Identifies the loading of an unsigned or untrusted DLL shortly after it has been dropped to disk via an SMB file transfer. This behavior is indicative of lateral movement techniques where an attacker transfers a malicious library over an administrative SMB share and immediately executes it on the remote host.

Back to all rules