Windows svchost.exe Loading newdev.dll from AppData Roaming (Potential Persistence)

Alerts on svchost.exe loading newdev.dll from AppData\Roaming, an unusual pattern consistent with stealthy persistence.

FreeReviewedSigma · High · v5
Product
windows
Category
image_load
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-02
Updated
2026-07-31

What it detects

Flags an image load where svchost.exe loads a DLL named newdev.dll located under the user’s AppData\Roaming path. Loading a DLL from Roaming rather than a standard system directory can indicate stealthy persistence or malicious staging using a legitimate Windows process. The detection relies on Windows image load telemetry providing both the loading process path and the loaded DLL path.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.