DLL-Based Persistence and Load Abuse: Search Order Hijacking, Side-Loading, COM Hijacking, AppInit and AppCert
A comprehensive map of how attackers abuse Windows DLL loading mechanisms: DLL search order hijacking (T1574.001), side-loading (T1574.002), phantom DLL, COM hijacking (T1546.015, InprocServer32/HKCU), AppInit_DLLs (T1546.010), AppCert DLLs (T1546.009), Netsh helper DLL (T1546.007), and Application Shimming (T1546.011). KnownDLLs and WinSxS protection mechanisms, Sysmon EID 7 (ImageLoad)-based detection, and SafeDllSearchMode hardening guide.
Swipe or use the arrows to move between sections
Zafiyet (Vulnerability)
Tehdit bağlamı, zafiyet ve istismar senaryosu
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Prevention & Hardening
Savunma teknolojileri, policy ve sertleştirme
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Detection
Davranış, loglama ve detection kuralları
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →