Windows utility loads untrusted DLL via image load telemetry
Flags DLL loads by InstallUtil/RegAsm/RegSvcs/regsvr32/rundll32 when the loaded DLL is unsigned or untrusted.
FreeUnreviewedSigmamediumv1
windows-utility-loads-untrusted-dll-via-image-load-telemetry-b5de0c9a
title: Windows utility loads untrusted DLL via image load telemetry
id: 04a79c4a-5835-40c5-8fe2-e205d49e1e59
status: test
description: This rule identifies when common Windows utilities (InstallUtil, RegAsm, RegSvcs, regsvr32, rundll32) load a DLL that is unsigned or has an untrusted SignatureStatus, based on image load events. Loading untrusted libraries through legitimate signed utilities can be used to proxy execution of malicious code while blending into normal system activity. It relies on Windows process image load telemetry and the DLL signature fields (Signed/SignatureStatus) to flag suspicious library loads.
references:
- https://www.elastic.co/security-labs/Hunting-for-Suspicious-Windows-Libraries-for-Execution-and-Evasion
- https://akhere.hashnode.dev/hunting-unsigned-dlls-using-kql
- https://unit42.paloaltonetworks.com/unsigned-dlls/?web_view=true
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_susp_unsigned_dll.yml
author: Swachchhanda Shrawan Poudel, Huntrule Team
date: 2024-02-28
modified: 2025-10-07
tags:
- attack.stealth
- attack.t1218.011
- attack.t1218.010
logsource:
product: windows
category: image_load
detection:
selection:
Image|endswith:
- \InstallUtil.exe
- \RegAsm.exe
- \RegSvcs.exe
- \regsvr32.exe
- \rundll32.exe
filter_main_signed:
Signed: "true"
filter_main_sig_status:
SignatureStatus:
- errorChaining
- errorCode_endpoint
- errorExpired
- trusted
- Valid
filter_main_signed_null:
Signed: null
filter_main_signed_empty:
Signed:
- ""
- "-"
filter_main_sig_status_null:
SignatureStatus: null
filter_main_sig_status_empty:
SignatureStatus:
- ""
- "-"
filter_main_windows_installer:
Image:
- C:\Windows\SysWOW64\rundll32.exe
- C:\Windows\System32\rundll32.exe
ImageLoaded|startswith: C:\Windows\Installer\
ImageLoaded|endswith:
- .tmp-\Microsoft.Deployment.WindowsInstaller.dll
- .tmp-\Avira.OE.Setup.CustomActions.dll
filter_main_assembly:
Image|startswith:
- C:\Windows\SysWOW64\
- C:\Windows\System32\
- C:\Windows\Microsoft.NET\Framework64
Image|endswith: \RegAsm.exe
ImageLoaded|endswith: .dll
ImageLoaded|startswith: C:\Windows\assembly\NativeImages
filter_optional_klite_codec:
Image:
- C:\Windows\SysWOW64\regsvr32.exe
- C:\Windows\System32\regsvr32.exe
ImageLoaded|startswith:
- C:\Program Files (x86)\K-Lite Codec Pack\
- C:\Program Files\K-Lite Codec Pack\
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: b5de0c9a-6f19-43e0-af4e-55ad01f550af
type: derived
What it detects
This rule identifies when common Windows utilities (InstallUtil, RegAsm, RegSvcs, regsvr32, rundll32) load a DLL that is unsigned or has an untrusted SignatureStatus, based on image load events. Loading untrusted libraries through legitimate signed utilities can be used to proxy execution of malicious code while blending into normal system activity. It relies on Windows process image load telemetry and the DLL signature fields (Signed/SignatureStatus) to flag suspicious library loads.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.