Hunting Rituals #1: Threat hunting for DLL side-loading
ID: 2c50c73f-bd79-5f92-92a0-6b14364859f6
STIX ID: report--2c50c73f-bd79-5f92-92a0-6b14364859f6
Feed Name: Group-IB Blog
This article introduces Group-IB’s Hunting Rituals series and demonstrates how to detect DLL side-loading (MITRE ATT&CK T1574.002) with Managed XDR/EDR telemetry by forming a hypothesis, crafting queries to find unsigned DLLs loaded by signed executables in suspicious directories, and pivoting via process GUIDs and scheduled task creation. Using an example involving Acrobat.exe/Acrobat.dll and schtasks.exe, it shows how to identify persistence and investigate related activity, noting that APTs such as TA428 and Dark Pink have leveraged this technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
