Potentially Suspicious Image Load of Offreg.dll

Rule Info

Name
Potentially Suspicious Image Load of Offreg.dll
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects potentially suspicious loading of the Offline Registry Library (offreg.dll). Offreg.dll enables direct read/write access to offline registry hives without invoking the Windows Registry API, bypassing its associated audit logging and telemetry. Attackers may abuse this to stealthily modify registry hives while evading detection mechanisms that rely on standard registry event logs.
Date
2026-07-23 00:00:00
Modified
None
Id
c9e5f013-4a6f-4d8c-9b0e-f7a4c3d26e95
Tags
attack.defense-impairment attack.persistence attack.t1112
Type
Community Rule

Rule History

Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #6169 from @swachchhanda000 - Add LegacyHive Indicators
2026-08-03