Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.9 KiB

Standards and References - DLL Sideloading Detection

MITRE ATT&CK Mappings

T1574.002 - Hijack Execution Flow: DLL Side-Loading

  • Tactic: Persistence (TA0003), Privilege Escalation (TA0004), Defense Evasion (TA0005)
  • Platforms: Windows
  • Data Sources: File monitoring, DLL monitoring, Process monitoring
Technique Name
T1574.001 DLL Search Order Hijacking
T1574.006 Dynamic Linker Hijacking
T1574.008 Path Interception by Search Order
T1574.009 Path Interception by Unquoted Service Path
T1574.011 Services Registry Permissions Weakness
T1574.012 COR_PROFILER

Windows DLL Search Order

  1. Directory of the executable (or directory specified by SetDllDirectory)
  2. System32 directory
  3. 16-bit system directory
  4. Windows directory
  5. Current working directory
  6. PATH environment variable directories

Known Vulnerable Applications

Application Vulnerable DLL Vendor Notes
OneDriveUpdater.exe version.dll Microsoft Frequently abused by APTs
Teams.exe CRYPTSP.dll Microsoft Side-loading target
DismHost.exe dismcore.dll Microsoft Signed binary side-loading
MpCmdRun.exe mpclient.dll Microsoft AV binary abuse
WerFault.exe dbgcore.dll Microsoft Error handler abuse
Grammarly Various Grammarly User-space application
Zoom Various Zoom Meeting application

Detection Data Sources

Source Event Purpose
Sysmon Event 7 Image Loaded DLL load with hash and signature
Sysmon Event 1 Process Create Application launch location
Windows Security 4688 Process Create Command line monitoring
ETW DLL Load Events Kernel-level DLL tracking
MDE DeviceImageLoadEvents DLL load telemetry