Potential DLL Sideloading Of MsCorSvc.DLL

Rule Info

Name
Potential DLL Sideloading Of MsCorSvc.DLL
Author
Wietze Beukema
Description
Detects potential DLL sideloading of "mscorsvc.dll".
Date
2024-07-11 00:00:00
Modified
2025-02-26 00:00:00
Id
cdb15e19-c2d0-432a-928e-e49c8c60dcf2
Tags
attack.privilege-escalation attack.persistence attack.defense-evasion attack.t1574.001
Type
Community Rule

Rule History

Author
Title
Date
Commit
phantinuss
chore: ci: bump validator version (#5722)
2025-10-23
Swachchhanda Shrawan Poudel
Merge PR #5208 from @swachchhanda000 - Fix FPs and added coverage for ARM based windows dotnet paths
2025-06-04
github-actions[bot]
Merge PR #5448 from @nasbench - Promote older rules status from `experimental` to `test`
2025-06-02
frack113
Merge PR #5418 from @frack113 - chore: 🧹 Update MITRE V17 DLL tags
2025-05-15
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
fornotes
Merge PR #4906 from @fornotes - Update and add new dll sideloading rules
2024-07-11