Potential DLL Sideloading Of MpSvc.DLL

Rule Info

Name
Potential DLL Sideloading Of MpSvc.DLL
Author
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema
Description
Detects potential DLL sideloading of "MpSvc.dll".
Date
2024-07-11 00:00:00
Modified
None
Id
5ba243e5-8165-4cf7-8c69-e1d3669654c1
Tags
attack.defense-evasion attack.t1574.002 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
fornotes
Merge PR #4906 from @fornotes - Update and add new dll sideloading rules
2024-07-11