← Back to SOC feed Coverage →

Files With System DLL Name In Unsuspected Locations

sigma MEDIUM SigmaHQ
T1036.005
imFileEvent
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at SigmaHQ →
Retrieved: 2026-03-25T02:50:08Z · Confidence: medium

Hunt Hypothesis

Adversaries may be using files with system DLL names in unexpected locations to evade detection and execute malicious code. SOC teams should proactively hunt for this behavior in Azure Sentinel to identify potential persistence or execution tactics early.

Detection Rule

Sigma (Original)

title: Files With System DLL Name In Unsuspected Locations
id: 13c02350-4177-4e45-ac17-cf7ca628ff5e
status: test
description: |
    Detects the creation of a file with the ".dll" extension that has the name of a System DLL in uncommon or unsuspected locations. (Outisde of "System32", "SysWOW64", etc.).
    It is highly recommended to perform an initial baseline before using this rule in production.
references:
    - Internal Research
author: Nasreddine Bencherchali (Nextron Systems)
date: 2024-06-24
tags:
    - attack.defense-evasion
    - attack.t1036.005
logsource:
    category: file_event
    product: windows
detection:
    selection:
        TargetFilename|endswith:
            # Note: Add more System DLL that can be abused for DLL sideloading to increase coverage
            - '\secur32.dll'
            - '\tdh.dll'
    filter_main_generic:
        # Note: It is recommended to use a more robust filter instead of this generic one, to avoid false negatives.
        TargetFilename|contains:
            # - '\SystemRoot\System32\'
            - 'C:\$WINDOWS.~BT\'
            - 'C:\$WinREAgent\'
            - 'C:\Windows\SoftwareDistribution\'
            - 'C:\Windows\System32\'
            - 'C:\Windows\SysWOW64\'
            - 'C:\Windows\WinSxS\'
            - 'C:\Windows\uus\'
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Third party software might bundle specific versions of system DLLs.
# Note: Upgrade to high after an initial baseline to your environement.
level: medium
regression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_creation_system_dll_files/info.yml

KQL (Azure Sentinel)

imFileEvent
| where (TargetFileName endswith "\\secur32.dll" or TargetFileName endswith "\\tdh.dll") and (not((TargetFileName contains "C:\\$WINDOWS.~BT\\" or TargetFileName contains "C:\\$WinREAgent\\" or TargetFileName contains "C:\\Windows\\SoftwareDistribution\\" or TargetFileName contains "C:\\Windows\\System32\\" or TargetFileName contains "C:\\Windows\\SysWOW64\\" or TargetFileName contains "C:\\Windows\\WinSxS\\" or TargetFileName contains "C:\\Windows\\uus\\")))

False Positive Guidance

MITRE ATT&CK Context

Original source: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_creation_system_dll_files.yml