Suspicious Loading of Dbgcore/Dbghelp DLLs from Unusual Location (via image_load)
This rule detects loading of dbgcore.dll or dbghelp.dll from uncommon locations such as user directories. These DLLs contain the MiniDumpWriteDump function, that can be misused for credential dumping purposes or in some cases for evading EDR/AV detection by suspending processes.
SigmahighWindowsv1
Full detection rule
Unlock this rule to view and copy it
Rule logic is available with an unlock credit. The public page keeps its context, mappings and implementation details visible.
Sign in to unlockKnown false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.