Windows DLL Load of RstrtMgr.dll by Uncommon Process
Alerts on non-standard processes loading RstrtMgr.dll using Windows image load telemetry.
FreeUnreviewedSigmalowv1
windows-dll-load-of-rstrtmgr-dll-by-uncommon-process-3669afd2
title: Windows DLL Load of RstrtMgr.dll by Uncommon Process
id: 3f19fc64-51de-451b-8564-adc1a899c0dd
related:
- id: b48492dc-c5ef-4572-8dff-32bc241c15c8
type: derived
- id: 3669afd2-9891-4534-a626-e5cf03810a61
type: derived
status: test
description: This rule identifies when a process loads the Restart Manager library (RstrtMgr.dll) via image-load telemetry where the loading process path is not in common Windows and installation-related locations. Attackers can leverage Restart Manager functionality to interfere with processes that lock files, supporting impact activities such as file encryption or disruption. The detection relies on Windows image load events matching RstrtMgr.dll by original filename and applying exclusions for typical system and installer paths.
references:
- https://www.crowdstrike.com/blog/windows-restart-manager-part-1/
- https://www.crowdstrike.com/blog/windows-restart-manager-part-2/
- https://web.archive.org/web/20231221193106/https://www.swascan.com/cactus-ransomware-malware-analysis/
- https://taiwan.postsen.com/business/88601/Hamas-hackers-use-data-destruction-software-BiBi-which-consumes-a-lot-of-processor-resources-to-wipe-Windows-computer-data--iThome.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_dll_rstrtmgr_uncommon_load.yml
author: Luc Génaux, Huntrule Team
date: 2023-11-28
modified: 2026-07-28
tags:
- attack.impact
- attack.defense-impairment
- attack.t1486
- attack.t1685
logsource:
category: image_load
product: windows
detection:
selection:
- ImageLoaded|endswith: \RstrtMgr.dll
- OriginalFileName: RstrtMgr.dll
filter_main_generic:
Image|startswith:
- C:\$WINDOWS.~BT\
- C:\$WinREAgent\
- C:\Program Files (x86)\
- C:\Program Files\
- C:\ProgramData\
- C:\Windows\explorer.exe
- C:\Windows\SoftwareDistribution\
- C:\Windows\SysNative\
- C:\Windows\System32\
- C:\Windows\SysWOW64\
- C:\Windows\WinSxS\
- C:\WUDownloadCache\
filter_main_user_software_installations:
Image|startswith: C:\Users\
Image|contains|all:
- \AppData\Local\Temp\is-
- .tmp\
Image|endswith: .tmp
filter_main_admin_software_installations:
Image|startswith: C:\Windows\Temp\
filter_optional_onedrive_1:
Image|startswith: C:\Users\
Image|endswith:
- \AppData\Local\Microsoft\OneDrive\OneDrive.exe
- \AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
filter_optional_onedrive_2:
Image|startswith: C:\Users\
Image|contains: \AppData\Local\Microsoft\OneDrive\
Image|endswith: \OneDrive.Sync.Service.exe
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Other legitimate Windows processes not currently listed
- Processes related to software installation
level: low
license: DRL-1.1
What it detects
This rule identifies when a process loads the Restart Manager library (RstrtMgr.dll) via image-load telemetry where the loading process path is not in common Windows and installation-related locations. Attackers can leverage Restart Manager functionality to interfere with processes that lock files, supporting impact activities such as file encryption or disruption. The detection relies on Windows image load events matching RstrtMgr.dll by original filename and applying exclusions for typical system and installer paths.
Known false positives
- Other legitimate Windows processes not currently listed
- Processes related to software installation
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.