==================================================

CREATED: WIN-DNS-SERVERPLUGINDLL (#1970)

Description

This detector identifies the installation of Windows DNS Server Level Plugin DLLs. This technique has been used by adversaries to load malicious DLLs on DNS servers which may also host Active Directory on Windows domains. 

ATT&CK Technique T1073

==================================================

CREATED: WIN-DHCP-CALLOUTDLL (#1971)

Description

This detector identifies the installation of a Windows DHCP Callout DLL. This technique has been used to load malicious code in a privileged context on Windows DHCP servers. 

ATT&CK Technique T1073

Did this answer your question?