Potential Rcdll.DLL Sideloading

Rule Info

Name
Potential Rcdll.DLL Sideloading
Author
X__Junior (Nextron Systems)
Description
Detects potential DLL sideloading of rcdll.dll
Date
2023-03-13 00:00:00
Modified
2023-03-15 00:00:00
Id
6e78b74f-c762-4800-82ad-f66787f10c8a
Tags
attack.defense_evasion attack.privilege_escalation attack.t1574.001 attack.t1574.002 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
github-actions[bot]
Merge PR #4700 from @nasbench - Promote older rules status from `experimental` to `test`
2024-02-01
Nasreddine Bencherchali
chore: author update
2023-04-12
Nasreddine Bencherchali
chore: increase level of some sideloading rules
2023-03-15
Nasreddine Bencherchali
fix: improve metadata
2023-03-13
Mohamed Ashraf (X__Junior)
new rules related to possible dll sideloading
2023-03-13