Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1055.001

T1055.001Dynamic-link Library Injection

T1055.001 — Dynamic-link Library Injection is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 8 detection use cases covering it and 3 threat-intel articles citing it.

Defense EvasionPrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
8Use cases
3Articles
0Sub-techniques
2Tactics

Use cases covering this technique (8)

Loading Of Dynwrapx Module ESCU actions · alerting P PowerShell PInvoke Process Injection API Chain ESCU actions · alerting P Windows Rasautou DLL Execution ESCU actions · alerting P Windows Uncommon Remote Thread Creation In Browser Process ESCU actions · hunting P Windows Process Injection Of Wermgr to Known Browser ESCU actions · alerting P [LLM] FudModule SYSTEM injection: msiexec.exe spawned by services.exe running as SYSTEM Bespoke exploit · alerting DSΣPDDCS [LLM] OctLurk/LurkProxy loader service registration (ServiceMain=RegisterService loading oleasapi.dll/msbasesysdc.dll) Bespoke install · alerting DSΣPDDCS [LLM] FrostyNeighbor Cobalt Strike beacon ViberPC.dll image load Bespoke install · hunting DSΣPDDCS

Articles citing this technique (3)