
Rule Info
Name
Potential JLI.dll Side-Loading
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects potential DLL side-loading of jli.dll.
JLI.dll has been observed being side-loaded by Java processes by various threat actors, including APT41, XWorm,
and others in order to load malicious payloads in context of legitimate Java processes.
Date
2025-07-25 00:00:00
Modified
None
Id
7a3b6d1f-4a2b-4f8c-9d7e-e9f8cbf21a35
Tags
attack.defense-evasion attack.persistence attack.privilege-escalation attack.t1574.001
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #5544 from @swachchhanda000 - Add `Potential JLI.dll Side-Loading`
2025-08-14