Windows utility loads untrusted DLL via image load telemetry

Flags DLL loads by InstallUtil/RegAsm/RegSvcs/regsvr32/rundll32 when the loaded DLL is unsigned or untrusted.

FreeUnreviewedSigmamediumv1
title: Windows utility loads untrusted DLL via image load telemetry
id: 04a79c4a-5835-40c5-8fe2-e205d49e1e59
status: test
description: This rule identifies when common Windows utilities (InstallUtil, RegAsm, RegSvcs, regsvr32, rundll32) load a DLL that is unsigned or has an untrusted SignatureStatus, based on image load events. Loading untrusted libraries through legitimate signed utilities can be used to proxy execution of malicious code while blending into normal system activity. It relies on Windows process image load telemetry and the DLL signature fields (Signed/SignatureStatus) to flag suspicious library loads.
references:
  - https://www.elastic.co/security-labs/Hunting-for-Suspicious-Windows-Libraries-for-Execution-and-Evasion
  - https://akhere.hashnode.dev/hunting-unsigned-dlls-using-kql
  - https://unit42.paloaltonetworks.com/unsigned-dlls/?web_view=true
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_susp_unsigned_dll.yml
author: Swachchhanda Shrawan Poudel, Huntrule Team
date: 2024-02-28
modified: 2025-10-07
tags:
  - attack.stealth
  - attack.t1218.011
  - attack.t1218.010
logsource:
  product: windows
  category: image_load
detection:
  selection:
    Image|endswith:
      - \InstallUtil.exe
      - \RegAsm.exe
      - \RegSvcs.exe
      - \regsvr32.exe
      - \rundll32.exe
  filter_main_signed:
    Signed: "true"
  filter_main_sig_status:
    SignatureStatus:
      - errorChaining
      - errorCode_endpoint
      - errorExpired
      - trusted
      - Valid
  filter_main_signed_null:
    Signed: null
  filter_main_signed_empty:
    Signed:
      - ""
      - "-"
  filter_main_sig_status_null:
    SignatureStatus: null
  filter_main_sig_status_empty:
    SignatureStatus:
      - ""
      - "-"
  filter_main_windows_installer:
    Image:
      - C:\Windows\SysWOW64\rundll32.exe
      - C:\Windows\System32\rundll32.exe
    ImageLoaded|startswith: C:\Windows\Installer\
    ImageLoaded|endswith:
      - .tmp-\Microsoft.Deployment.WindowsInstaller.dll
      - .tmp-\Avira.OE.Setup.CustomActions.dll
  filter_main_assembly:
    Image|startswith:
      - C:\Windows\SysWOW64\
      - C:\Windows\System32\
      - C:\Windows\Microsoft.NET\Framework64
    Image|endswith: \RegAsm.exe
    ImageLoaded|endswith: .dll
    ImageLoaded|startswith: C:\Windows\assembly\NativeImages
  filter_optional_klite_codec:
    Image:
      - C:\Windows\SysWOW64\regsvr32.exe
      - C:\Windows\System32\regsvr32.exe
    ImageLoaded|startswith:
      - C:\Program Files (x86)\K-Lite Codec Pack\
      - C:\Program Files\K-Lite Codec Pack\
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: medium
license: DRL-1.1
related:
  - id: b5de0c9a-6f19-43e0-af4e-55ad01f550af
    type: derived

What it detects

This rule identifies when common Windows utilities (InstallUtil, RegAsm, RegSvcs, regsvr32, rundll32) load a DLL that is unsigned or has an untrusted SignatureStatus, based on image load events. Loading untrusted libraries through legitimate signed utilities can be used to proxy execution of malicious code while blending into normal system activity. It relies on Windows process image load telemetry and the DLL signature fields (Signed/SignatureStatus) to flag suspicious library loads.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.