
Rule Info
Name
PowerPoint PPCore.dll Sideloading Attempt
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects potential DLL sideloading attempts through PowerPoint.exe loading ppcore.dll from suspicious locations.
Adversary have been also observed using renamed powerpoint.exe to sideload ppcore.dll possibly to bypass detection.
Date
2025-04-23 00:00:00
Modified
None
Id
1a2b3c4d-5e6f-7890-abcd-ef1234567890
Tags
attack.defense-evasion attack.persistence attack.t1574.001
Type
Nextron Sigma feed only (private)