Potential Ctxmui.DLL Sideloading

Rule Info

Name
Potential Ctxmui.DLL Sideloading
Author
X__Junior (Nextron Systems)
Description
Detects potential DLL sideloading of "ctxmui.dll"
Date
2026-07-12 00:00:00
Modified
None
Id
6dfe096f-ed4f-4ba5-9617-b3c29209f487
Tags
attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001
Type
Nextron Sigma feed only (private)

Rule History