Windows: Detect dnscmd.exe setting ServerLevelPluginDll to install DNS plugin DLL

Flags dnscmd.exe DNS configuration that sets ServerLevelPluginDll, indicating potential malicious DNS server code injection.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-05-08
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies process executions of dnscmd.exe where the command line includes both /config and /serverlevelplugindll, indicating a DNS ServerLevelPluginDll has been set. Attackers can use this behavior to load a malicious plugin DLL by leveraging the DNS server context, typically requiring a restart to take effect. Telemetry relies on Windows process creation logs capturing the executable path and full command line arguments.

Related detections9 linkedT1574.001 — drag to rearrange
Windows Registry Modification: OracleOciLib/OracleOciLibPath Under MSDTC for oci.dll Redirection
Windows Registry: DHCP Server Callout DLL and Enable Parameters Installation
Windows DNS ServerLevelPluginDll Registry Installation
Suspicious Service DLL Hijack of IKEEXT or PrintNotify
Malicious PowerShell Spawned by Masqueraded NVIDIA GeForce Experience Binary
Suspicious msimg32.dll Loaded from Non-System Directory
DLL Side-Loading via Signed Binary Loading Known Malicious Helper DLL
Malicious Enabling of Restricted Admin Mode via Registry by UAT-8837
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Windows: Detect dnscmd.exe setting ServerLevelPluginDll to install DNS plugin DLL
Pivot detection · T1574.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.