DLL Search Order Hijacking via Sysmon FileCreate and ImageLoad Correlation
This rule monitors for scenarios where a DLL is created and subsequently loaded by a process within a short time frame (60 seconds or less). The rule specifically excludes files located in 'C:\Windows\' and 'C:\Program Files\' to minimize noise, focusing on suspicious modules originating from user-writable or unexpected locations, which is a common behavior of malware or side-loading attacks.
Splunk (SPL)

