Windows Image Load: coregen.exe Potential DLL Sideloading

Identifies potential DLL sideloading when coregen.exe loads DLLs outside expected system and Silverlight locations.

FreeReviewedSigma · Medium · v2
Product
windows
Category
image_load
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-12-31
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

Identifies execution of coregen.exe followed by DLL image loads, where the loaded DLL path is not one of the expected system or Microsoft Silverlight directories. Attackers can abuse coregen.exe to load attacker-supplied or non-standard DLLs, supporting stealthy execution and potential privilege escalation. The rule relies on image load telemetry that includes the loading process path and the loaded DLL path.

Related detections9 linkedT1055 — drag to rearrange
Malicious aspnet_compiler.exe Injection Host Spawned by PowerShell via process_creation
Suspicious RegAsm or RegSvcs Spawned by Script Host (via process_creation)
Windows: Files created by Microsoft Sync Center (mobsync.exe) with .dll/.exe extensions
Windows Microsoft Sync Center (mobsync.exe) Network Connections to Public IPs
Suspicious Office Application Spawning Script Or Shell Interpreter
Suspicious Network Connection From wabmig.exe (Turian Injection)
Suspicious Outbound Network Connection from Explorer Process
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Windows Image Load: coregen.exe Potential DLL Sideloading
Pivot detection · T1055 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.