Technique T1574
Hijack Execution Flow
Detection & mitigation
Monitor for suspicious DLL loads from unusual locations or unsigned DLLs loaded by legitimate executables. Use application control and endpoint detection to flag DLL sideloading attempts, and educate users about opening unsolicited archives.