Windows DLL Load of RstrtMgr.dll by Uncommon Process

Alerts on non-standard processes loading RstrtMgr.dll using Windows image load telemetry.

FreeUnreviewedSigmalowv1
title: Windows DLL Load of RstrtMgr.dll by Uncommon Process
id: 3f19fc64-51de-451b-8564-adc1a899c0dd
related:
  - id: b48492dc-c5ef-4572-8dff-32bc241c15c8
    type: derived
  - id: 3669afd2-9891-4534-a626-e5cf03810a61
    type: derived
status: test
description: This rule identifies when a process loads the Restart Manager library (RstrtMgr.dll) via image-load telemetry where the loading process path is not in common Windows and installation-related locations. Attackers can leverage Restart Manager functionality to interfere with processes that lock files, supporting impact activities such as file encryption or disruption. The detection relies on Windows image load events matching RstrtMgr.dll by original filename and applying exclusions for typical system and installer paths.
references:
  - https://www.crowdstrike.com/blog/windows-restart-manager-part-1/
  - https://www.crowdstrike.com/blog/windows-restart-manager-part-2/
  - https://web.archive.org/web/20231221193106/https://www.swascan.com/cactus-ransomware-malware-analysis/
  - https://taiwan.postsen.com/business/88601/Hamas-hackers-use-data-destruction-software-BiBi-which-consumes-a-lot-of-processor-resources-to-wipe-Windows-computer-data--iThome.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_dll_rstrtmgr_uncommon_load.yml
author: Luc Génaux, Huntrule Team
date: 2023-11-28
modified: 2026-07-28
tags:
  - attack.impact
  - attack.defense-impairment
  - attack.t1486
  - attack.t1685
logsource:
  category: image_load
  product: windows
detection:
  selection:
    - ImageLoaded|endswith: \RstrtMgr.dll
    - OriginalFileName: RstrtMgr.dll
  filter_main_generic:
    Image|startswith:
      - C:\$WINDOWS.~BT\
      - C:\$WinREAgent\
      - C:\Program Files (x86)\
      - C:\Program Files\
      - C:\ProgramData\
      - C:\Windows\explorer.exe
      - C:\Windows\SoftwareDistribution\
      - C:\Windows\SysNative\
      - C:\Windows\System32\
      - C:\Windows\SysWOW64\
      - C:\Windows\WinSxS\
      - C:\WUDownloadCache\
  filter_main_user_software_installations:
    Image|startswith: C:\Users\
    Image|contains|all:
      - \AppData\Local\Temp\is-
      - .tmp\
    Image|endswith: .tmp
  filter_main_admin_software_installations:
    Image|startswith: C:\Windows\Temp\
  filter_optional_onedrive_1:
    Image|startswith: C:\Users\
    Image|endswith:
      - \AppData\Local\Microsoft\OneDrive\OneDrive.exe
      - \AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
  filter_optional_onedrive_2:
    Image|startswith: C:\Users\
    Image|contains: \AppData\Local\Microsoft\OneDrive\
    Image|endswith: \OneDrive.Sync.Service.exe
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Other legitimate Windows processes not currently listed
  - Processes related to software installation
level: low
license: DRL-1.1

What it detects

This rule identifies when a process loads the Restart Manager library (RstrtMgr.dll) via image-load telemetry where the loading process path is not in common Windows and installation-related locations. Attackers can leverage Restart Manager functionality to interfere with processes that lock files, supporting impact activities such as file encryption or disruption. The detection relies on Windows image load events matching RstrtMgr.dll by original filename and applying exclusions for typical system and installer paths.

Known false positives

  • Other legitimate Windows processes not currently listed
  • Processes related to software installation

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.