Compliance Node Overview
MITRE ATT&CK T1574.002 (DLL Side-Loading) is an Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by side-loading DLLs. Similar to DLL Search Order Hijacking, side-loading involves hijacking which DLL a program loads. But rather than just planting the DLL within the search order of a program then waiting for the victim application to be invoked, adversaries may directly side-load their payloads by planting then invoking a legitimate application that executes their payload(s). Affected platforms: Windows. MITRE-documented mitigations include M1051 Update Software, M1013 Application Developer Guidance, M1022 Restrict File and Directory Permissions, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CA-07, CM-02, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/versions/v16/techniques/T1574/002/
SHA-256 integrity: 42fe41fedc9bd4b86a625d40e8a16cadb370a4acb25698bef881973dc75974aa
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1574.002: DLL Side-Loading (https://attack.mitre.org/versions/v16/techniques/T1574/002/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access