Data Source
DeviceImageLoadEvents
2 queries tagged with this data source.
-
Analytics Rules
Detect Dll Masquerading As Microsoft Defender
DLLs pretending to be Microsoft Defender via resource-level publisher/original-filename metadata — a Vidar Stealer TTP.
-
Analytics Rules
Detect Unsigned Dll Load Verified Signing State
Unsigned DLL loads, using IsSigned/SigningStatus rather than treating an empty SHA256 as unsigned (the field is documented as usually-populated, not always).