Files
blue-team-tools/deprecated/windows/image_load_side_load_scm.yml
T
frack113 83b9ff50bc Merge PR #5418 from @frack113 - chore: 🧹 Update MITRE V17 DLL tags
chore: Update MITRE T1574.002 as is now merge into T1574.001 in the V17
2025-05-15 12:17:10 +02:00

33 lines
1.0 KiB
YAML

title: SCM DLL Sideload
id: bc3cc333-48b9-467a-9d1f-d44ee594ef48
related:
- id: 602a1f13-c640-4d73-b053-be9a2fa58b77
type: similar
status: deprecated
description: Detects DLL sideloading of DLLs that are loaded by the SCM for some services (IKE, IKEEXT, SessionEnv) which do not exists on a typical modern system
references:
- https://decoded.avast.io/martinchlumecky/png-steganography/
- https://posts.specterops.io/lateral-movement-scm-and-dll-hijacking-primer-d2f61e8ab992
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022/12/01
modified: 2023/02/14
tags:
- attack.defense_evasion
- attack.persistence
- attack.privilege_escalation
- attack.t1574.001
logsource:
category: image_load
product: windows
detection:
selection:
ImageLoaded:
- 'C:\Windows\System32\WLBSCTRL.dll'
- 'C:\Windows\System32\TSMSISrv.dll'
- 'C:\Windows\System32\TSVIPSrv.dll'
Image: 'C:\Windows\System32\svchost.exe'
condition: selection
falsepositives:
- Unknown
level: medium