← Back to SOC feed Coverage →

IsDLL

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-22T11:00:00Z · Confidence: medium

Hunt Hypothesis

This rule identifies processes that are loaded as dynamic-link libraries, a common technique adversaries use to inject malicious code into legitimate processes or hide their presence through process hollowing. Proactively hunting for these artifacts in Azure Sentinel allows the SOC to detect subtle fileless or in-memory attacks that traditional endpoint detections might miss due to their low severity and reliance on standard OS mechanisms.

YARA Rule

rule IsDLL : PECheck
{
	condition:
		// MZ signature at offset 0 and ...
		uint16(0) == 0x5A4D and
		// ... PE signature at offset stored in MZ header at 0x3C
		(uint16(uint32(0x3C)+0x16) & 0x2000) == 0x2000

}

Deployment Notes

This YARA rule can be deployed in the following contexts:

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer_compiler_signatures.yar