<<< Hide Navigation Hide TOC >>>
Suspicious DLL Loaded via CertOC.EXE (84232095-ecca-4015-b0d7-7726507ee793)
Detects when a user installs certificates by using CertOC.exe to load the target DLL file.
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
Suspicious DLL Loaded via CertOC.EXE (84232095-ecca-4015-b0d7-7726507ee793) | Sigma-Rules | System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) | Attack Pattern | 1 |