APT29 GRAPELOADER Suspicious DLL Load with Network Connection
This rule detects instances where a process loads a DLL from suspicious, commonly user-writable directories (such as Temp, AppData, ProgramData, or Public). It filters for DLLs that lack standard file metadata (FileVersion/Description) or contain an OriginalFileName mismatch, which is often indicative of side-loading or malicious library injection. The rule further correlates this event with a network connection initiated by the same process to highlight potential C2 activity associated with the suspicious DLL load.
Splunk (SPL)

