Manipulation of AppInit DLL loading list
The AppInit DLLs Registry key contains a list of DLLs that will be loaded when user32.dll is loaded. As most Windows executables use the user32.dll, any DLL that is listed in the AppInit_DLLs Registry key will be loaded also. The user32.dll file is also used by processes that are automatically started by the system when you log on.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
Registry action type = all AND os actor process signature vendor != Malwarebytes Inc AND Symantec Corporation AND AppSense AND Sophos Ltd AND Sophos Limited AND Ivanti, Inc. AND registry data != *system32\SophosAV\* AND *\Citrix\* AND registry data = *.dll AND registry key name = *Software\Microsoft\Windows NT\CurrentVersion\Windows* AND registry value name = AppInit_DLLs Process initiator signer != Malwarebytes Inc AND Symantec Corporation AND AppSense AND Sophos Ltd AND Sophos Limited AND Ivanti, Inc. AND cgo signer != Malwarebytes Inc AND Symantec Corporation AND AppSense AND Sophos Ltd AND Sophos Limited AND Ivanti, Inc. AND initiator signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash , cgo signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash , os parent signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash Host host os = windows
Preventable: yes