Windows DNS Server error when loading ServerLevelPlugin DLL fails
Flags Windows DNS Server errors where the ServerLevelPluginDLL plugin DLL fails to load.
- Product
- windows
- Service
- dns-server
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2017-05-08
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Windows DNS Server errors where the DNS server fails to load a specified ServerLevelPlugin DLL referenced in the registry. Attackers and administrators rely on plugin DLL loading for persistence and stealth, and repeated failures can indicate tampering with plugin registrations or attempted use of unauthorized components. The detection is based on DNS Server event telemetry using Event IDs 150, 770, and 771.
Reporting behind it
- medium.comhttps://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83
- technet.microsoft.comhttps://technet.microsoft.com/en-us/library/cc735829(v=ws.10).aspx
- twitter.comhttps://twitter.com/gentilkiwi/status/861641945944391680
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/dns_server/win_dns_server_susp_server_level_plugin_dll.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows DNS Server error when loading ServerLevelPlugin DLL fails
id: c2fd46d5-a89b-4e6e-ab35-d98b832150ce
related:
- id: e61e8a88-59a9-451c-874e-70fcc9740d67
type: derived
- id: f63b56ee-3f79-4b8a-97fb-5c48007e8573
type: derived
- id: cbe51394-cd93-4473-b555-edf0144952d9
type: derived
status: test
description: This rule identifies Windows DNS Server errors where the DNS server fails to load a specified ServerLevelPlugin DLL referenced in the registry. Attackers and administrators rely on plugin DLL loading for persistence and stealth, and repeated failures can indicate tampering with plugin registrations or attempted use of unauthorized components. The detection is based on DNS Server event telemetry using Event IDs 150, 770, and 771.
references:
- https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83
- https://technet.microsoft.com/en-us/library/cc735829(v=ws.10).aspx
- https://twitter.com/gentilkiwi/status/861641945944391680
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/dns_server/win_dns_server_susp_server_level_plugin_dll.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-05-08
modified: 2023-02-05
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
product: windows
service: dns-server
detection:
selection:
EventID:
- 150
- 770
- 771
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1