Windows File Creation: Non-Existent System DLLs in System32
Alerts when targeted non-existent system DLL filenames are created in Windows system directories, indicating potential DLL hijacking setup.
FreeUnreviewedSigmamediumv1
windows-file-creation-non-existent-system-dlls-in-system32-df6ecb8b
title: "Windows File Creation: Non-Existent System DLLs in System32"
id: 53b9eab0-8d2a-416e-9599-6b49c3aa64b7
related:
- id: 6b98b92b-4f00-4f62-b4fe-4d1920215771
type: similar
- id: df6ecb8b-7822-4f4b-b412-08f524b4576c
type: derived
status: test
description: This rule flags creation of specific DLL filenames that are typically not present on a system, with paths pointing to system directories such as \Windows\System32. Creating these DLLs can indicate preparation for DLL preloading or search-order abuse where a legitimate process may load an attacker-controlled library. It relies on Windows file event telemetry that records when these targeted DLLs are created at the specified paths.
references:
- http://remoteawesomethoughts.blogspot.com/2019/05/windows-10-task-schedulerservice.html
- https://clement.notin.org/blog/2020/09/12/CVE-2020-7315-McAfee-Agent-DLL-injection/
- https://decoded.avast.io/martinchlumecky/png-steganography/
- https://github.com/blackarrowsec/redteam-research/tree/26e6fc0c0d30d364758fa11c2922064a9a7fd309/LPE%20via%20StorSvc
- https://github.com/Wh04m1001/SysmonEoP
- https://itm4n.github.io/cdpsvc-dll-hijacking/
- https://posts.specterops.io/lateral-movement-scm-and-dll-hijacking-primer-d2f61e8ab992
- https://securelist.com/passiveneuron-campaign-with-apt-implants-and-cobalt-strike/117745/
- https://www.crowdstrike.com/en-us/blog/4-ways-adversaries-hijack-dlls/
- https://www.hexacorn.com/blog/2013/12/08/beyond-good-ol-run-key-part-5/
- https://www.hexacorn.com/blog/2025/06/14/wermgr-exe-boot-offdmpsvc-dll-lolbin/
- https://www.hexacorn.com/blog/2025/06/14/wpr-exe-boottrace-phantom-dll-axeonoffhelper-dll-lolbin/
- https://x.com/0gtweet/status/1564131230941122561
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_create_non_existent_dlls.yml
author: Nasreddine Bencherchali (Nextron Systems), fornotes, Huntrule Team
date: 2022-12-01
modified: 2026-01-24
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|endswith:
- :\Windows\System32\axeonoffhelper.dll
- :\Windows\System32\cdpsgshims.dll
- :\Windows\System32\oci.dll
- :\Windows\System32\offdmpsvc.dll
- :\Windows\System32\shellchromeapi.dll
- :\Windows\System32\TSMSISrv.dll
- :\Windows\System32\TSVIPSrv.dll
- :\Windows\System32\wbem\wbemcomn.dll
- :\Windows\System32\WLBSCTRL.dll
- :\Windows\System32\wow64log.dll
- :\Windows\System32\WptsExtensions.dll
- \SprintCSP.dll
condition: selection
falsepositives:
- Unknown
level: medium
regression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_create_non_existent_dlls/info.yml
license: DRL-1.1
What it detects
This rule flags creation of specific DLL filenames that are typically not present on a system, with paths pointing to system directories such as \Windows\System32. Creating these DLLs can indicate preparation for DLL preloading or search-order abuse where a legitimate process may load an attacker-controlled library. It relies on Windows file event telemetry that records when these targeted DLLs are created at the specified paths.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.