Suspicious AppCertDlls Registry Modification for DLL Injection

PremiumReviewedSigma · High · v1
Category
registry_set
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation or modification of AppCertDlls registry values, which load a specified DLL into any process that calls the Win32 process-creation APIs. Attackers abuse this key for stealthy code injection and persistence across newly spawned processes.

Related detections2 linkedT1546.009 — drag to rearrange
Windows Registry Session Manager ASEP Modification via Auto-Start Extensibility Points
Windows Registry: AppCertDlls NewName/TargetObject Creation for DLL Load Persistence
Suspicious AppCertDlls Registry Modification for DLL Injection
Pivot detection · T1546.009 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.