Windows Registry: AppCertDlls NewName/TargetObject Creation for DLL Load Persistence

Alerts on Windows registry changes involving AppCertDlls paths that can enable malicious DLL loading for persistence.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_event
Author
Ilyas Ochkov, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-25
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags registry events where the AppCertDlls value for the Session Manager location is created or modified via a detected TargetObject or NewName path. Attackers can abuse AppCertDlls to force a malicious DLL to be loaded into separate processes, supporting persistence and potential privilege escalation. Telemetry is based on Windows registry event logs capturing TargetObject and NewName for the AppCertDlls registry path.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.