LoFP LoFP / other dlls with the same imphash

Techniques

Sample rules

HackTool - SharpEvtMute DLL Load

Description

Detects the load of EvtMuteHook.dll, a key component of SharpEvtHook, a tool that tampers with the Windows event logs

Detection logic

condition: selection
selection:
  Hashes|contains: IMPHASH=330768A4F172E10ACB6287B87289D83B