Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths

Alerts when BaaUpdate.exe loads DLLs from Temp/Public-type locations associated with DLL search hijacking risk.

FreeReviewedSigma · High · v2
Product
windows
Category
image_load
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-10-18
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags executions of baaupdate.exe that load DLL files from locations commonly writable by non-admin users, such as Temp, Public, and Default user directories. Loading DLLs from these paths can indicate COM hijacking or other DLL search-order abuse intended to execute attacker-controlled code in the context of the logged-on user. It relies on image load telemetry showing the loaded DLL path and the process image ending with BaaUpdate.exe.

Related detections9 linkedT1218 — drag to rearrange
Windows SpeechRuntime.exe Child Process Creation
Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
Malicious Impacket DCOMexec Process Abuse via MMC (via process_creation)
Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)
Malicious aspnet_compiler.exe Injection Host Spawned by PowerShell via process_creation
Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path
Suspicious RegAsm or RegSvcs Spawned by Script Host (via process_creation)
Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths
Pivot detection · T1218 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.