{"id":"T1546.010","name":"AppInit DLLs","url":"https://attack.mitre.org/techniques/T1546/010","tactics":["privilege-escalation","persistence"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0557","stix_id":"x-mitre-detection-strategy--6f59bdfc-8352-4e6f-bef1-cc59b4e9b04d","name":"Detection Strategy for Event Triggered Execution: AppInit DLLs (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0557","analytics":[{"id":"AN1536","stix_id":"x-mitre-analytic--e886b9c8-2187-4363-9043-1e5c60d75363","name":"Analytic 1536","description":"Registry key modification to AppInit_DLLs value followed by anomalous DLL loading by processes importing user32.dll, especially unsigned or uncommon DLLs, suggesting unauthorized AppInit persistence or privilege escalation.","url":"https://attack.mitre.org/detectionstrategies/DET0557#AN1536","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ImagePathWhitelist","description":"Paths or filenames of known-good DLLs to exclude from alerting"},{"field":"UserContext","description":"Context of the user modifying the registry key (e.g., admin vs standard user)"},{"field":"TimeWindow","description":"Temporal threshold for correlating registry modification and DLL load"},{"field":"DLLSignatureStatus","description":"Filter or flag unsigned or suspiciously signed DLLs"}],"live":true,"detection_strategies":["DET0557"],"techniques":["T1546.010"]}],"live":true,"version":"1.0","techniques":["T1546.010"]}],"sigma_rules":[{"id":"4f84b697-c9ed-4420-8ab5-e09af5b2345d","title":"New DLL Added to AppInit_DLLs Registry Key","author":"Ilyas Ochkov, oscd.community, Tim Shelton","status":"test","level":"medium","date":"2019-10-25","modified":"2022-12-25","description":"DLLs that are specified in the AppInit_DLLs value in the Registry key HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows are loaded by user32.dll into every process that loads user32.dll","references":["https://eqllib.readthedocs.io/en/latest/analytics/822dc4c5-b355-4df8-bd37-29c458997b8f.html"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.010"],"path":"rules/windows/registry/registry_event/registry_event_new_dll_added_to_appinit_dlls_registry_key.yml","techniques":["T1546.010"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}