detecting-dll-sideloading-attacks

mukul975/detecting-dll-sideloading-attacks · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. hunting-for-living-off-the-land-binaries · mukul975 bundle
    Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.
    24.6k
    repo stars
  2. detecting-service-account-abuse · mukul975 bundle
    Detect abuse of service accounts through anomalous interactive logons, privilege escalation, lateral movement, and unauthorized access patterns.
    24.6k
    repo stars
  3. hunting-for-webshell-activity · mukul975 bundle
    Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.
    24.6k
    repo stars
  4. detecting-privilege-escalation-attempts · mukul975 bundle
    Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.
    24.6k
    repo stars
  5. hunting-for-unusual-network-connections · mukul975 bundle
    Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.
    24.6k
    repo stars
  6. detecting-process-hollowing-technique · mukul975 bundle
    Detect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.
    24.6k
    repo stars

Frequently asked questions

How do I install the detecting-dll-sideloading-attacks skill?

Run npx skillmds add mukul975/detecting-dll-sideloading-attacks in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the detecting-dll-sideloading-attacks skill do?

Detect DLL side-loading attacks where adversaries place malicious DLLs alongside legitimate applications to hijack execution flow for defense evasion. It is listed under Security, Coding & Dev Tools, Vulnerability Scanning on SkillMD.

Is detecting-dll-sideloading-attacks safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with detecting-dll-sideloading-attacks?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is detecting-dll-sideloading-attacks free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published detecting-dll-sideloading-attacks?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.