<<< Hide Navigation Hide TOC >>>
DotNET Assembly DLL Loaded Via Office Application (ff0f2b05-09db-4095-b96d-1b75ca24894a)
Detects any assembly DLL being loaded by an Office Product
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
Malicious File - T1204.002 (232b7f21-adf9-4b42-b936-b9d6f7df856e) | Attack Pattern | DotNET Assembly DLL Loaded Via Office Application (ff0f2b05-09db-4095-b96d-1b75ca24894a) | Sigma-Rules | 1 |
Malicious File - T1204.002 (232b7f21-adf9-4b42-b936-b9d6f7df856e) | Attack Pattern | User Execution - T1204 (8c32eb4d-805f-4fc5-bf60-c4d476c131b5) | Attack Pattern | 2 |