Potential Rcdll.DLL Sideloading

Rule Info

Tags
attack.defense_evasion attack.t1574.001 DEMO attack.privilege_escalation attack.t1574.002
Modified
2023-03-15 00:00:00
Author
X__Junior
Name
Potential Rcdll.DLL Sideloading
Description
Detects potential DLL sideloading of rcdll.dll
Date
2023-03-13 00:00:00
Id
6e78b74f-c762-4800-82ad-f66787f10c8a
Type
Community Rule

Rule History

Commit
Date
Author
Title
2023-03-15
Nasreddine Bencherchali
chore: increase level of some sideloading rules
2023-03-13
Nasreddine Bencherchali
fix: improve metadata
2023-03-13
Mohamed Ashraf (X__Junior)
new rules related to possible dll sideloading