Windows DNS Server Plugin DLL Load Failure (ServerLevelPluginDLL) via DNS Server Errors

Flags Windows DNS Server errors where the ServerLevelPluginDLL plugin DLL fails to load.

FreeUnreviewedSigmahighv1
title: Windows DNS Server Plugin DLL Load Failure (ServerLevelPluginDLL) via DNS Server Errors
id: c2fd46d5-a89b-4e6e-ab35-d98b832150ce
related:
  - id: e61e8a88-59a9-451c-874e-70fcc9740d67
    type: derived
  - id: f63b56ee-3f79-4b8a-97fb-5c48007e8573
    type: derived
  - id: cbe51394-cd93-4473-b555-edf0144952d9
    type: derived
status: test
description: This rule identifies DNS Server error events indicating that a ServerLevelPluginDLL plugin DLL could not be loaded. Attackers may leverage DNS server extensibility to persist or execute code by adding or modifying plugins, so load failures can signal tampering attempts or misconfiguration during malicious changes. It relies on DNS Server telemetry from Windows events with Event IDs 150, 770, and 771.
references:
  - https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83
  - https://technet.microsoft.com/en-us/library/cc735829(v=ws.10).aspx
  - https://twitter.com/gentilkiwi/status/861641945944391680
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/dns_server/win_dns_server_susp_server_level_plugin_dll.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-05-08
modified: 2023-02-05
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.execution
  - attack.stealth
  - attack.t1574.001
logsource:
  product: windows
  service: dns-server
detection:
  selection:
    EventID:
      - 150
      - 770
      - 771
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule identifies DNS Server error events indicating that a ServerLevelPluginDLL plugin DLL could not be loaded. Attackers may leverage DNS server extensibility to persist or execute code by adding or modifying plugins, so load failures can signal tampering attempts or misconfiguration during malicious changes. It relies on DNS Server telemetry from Windows events with Event IDs 150, 770, and 771.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.