
Rule Info
Name
VMMap Signed Dbghelp.DLL Potential Sideloading
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects potential DLL sideloading of a signed dbghelp.dll by the Sysinternals VMMap.
Date
2023-09-05 00:00:00
Modified
None
Id
98ffaed4-aec2-4e04-9b07-31492fe68b3d
Tags
attack.defense_evasion attack.persistence attack.privilege_escalation attack.t1574.001 attack.t1574.002 DEMO
Type
Community Rule
Link to Public Repo