LoFP LoFP / some installers may trigger some false positives

Techniques

Sample rules

Potential ShellDispatch.DLL Sideloading

Description

Detects potential DLL sideloading of “ShellDispatch.dll”

Detection logic

condition: selection and not 1 of filter_main_*
filter_main_legit_path:
- ImageLoaded|contains|all:
  - :\Users\
  - \AppData\Local\Temp\
- ImageLoaded|contains: :\Windows\Temp\
selection:
  ImageLoaded|endswith: \ShellDispatch.dll