// REFERENCE

Sysmon 7 — Image (DLL) loaded

Log: Sysmon/Operational Medium risk

A process loaded an image/DLL (Sysmon; usually filtered for noise). Key to detecting DLL sideloading: a legitimate binary loading an unsigned DLL from an unusual path. Look at the signature status and the path.

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.