Malicious DLL Sideload via SentinelBrowserNativeHost

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects SentinelBrowserNativeHost.exe loading SentinelAgentCore.dll from a directory outside the legitimate SentinelOne installation path, indicating DLL sideloading used to run Cephalus ransomware loader code under a trusted signed binary. The rogue DLL pairs with a data.bin payload to decrypt and execute the ransomware. Abusing a security vendor binary for sideloading evades trust-based defenses.

Related detections9 linkedT1574.001 — drag to rearrange
Suspicious jli.dll Sideloading by Non-Java Trusted Binary
Suspicious version.dll Sideloading via ADExplorer
Suspicious Application Config File Dropped Beside Trusted .NET Binary for App Domain Manager Injection
Suspicious Acrobat.exe Loading Co-located DLL from ProgramData
Suspicious IntelAudioService Execution with StateRepository Arguments via SPECTRALVIPER
Malicious Kazuar DLL Side-Loading via Renamed Host Binaries
Malicious Lazarus DLL Side-Loading via Colorcpl from ProgramData (via process_creation)
Malicious Lazarus DLL Side-Loading via PresentationHost from Non-Standard Path (via process_creation)
Suspicious msvc_4.dll Side-Load from Typosquatted NVIDlA Directory via Image Load
Malicious DLL Sideload via SentinelBrowserNativeHost
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.