Skip to content
Sysmon

Sysmon Event ID 7: Image (DLL) loaded

Image loadedSysmon event 7 logs a DLL or other module loaded into a process, with hashes and signature. Used to catch DLL side-loading and unusual module loads.
7
Event ID
7
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Processes
Default logging
Needs configuration

What event 7 means

Sysmon event 7 records a module being mapped into a process: the host process (Image), the loaded file (ImageLoaded), its hashes, version information and signature status.

Logging every module load would produce enormous volume, so the event is off by default and must be targeted. Typical rules watch for specific DLLs loaded by unexpected processes (for example the PowerShell automation DLL loaded outside PowerShell, or dbghelp.dll / dbgcore.dll loaded by a tool that then touches LSASS), and for unsigned DLLs loaded from user-writable folders.

For DLL side-loading, the telltale pattern is a signed legitimate executable running from an unusual folder and loading an unsigned DLL from the same folder.

When it is logged

Audit policy / configuration

Sysmon installed with image load monitoring enabled (-l switch or an <ImageLoad> rule in the configuration). Use narrow include rules; logging all loads is very noisy.

Key fields

FieldWhat it tells you
ProcessGuidProcess that loaded the module; pivot to its event 1.
ImageExecutable of the loading process.
ImageLoadedFull path of the loaded module.
OriginalFileNameInternal name of the module from its version resource; reveals renamed DLLs.
HashesHashes of the loaded module.
Signedtrue or false: whether the module is signed.
SignatureSigner of the module.
SignatureStatusValidation result of the signature, e.g. Valid.
UserAccount of the loading process (newer Sysmon versions).

Common benign sources

  • Applications loading their own DLLs from their install folders.
  • Security and monitoring products injecting their modules into many processes.

What attackers do that produces it

  • DLL side-loading — a signed executable copied to ProgramData or %TEMP% loading an unsigned DLL placed next to it.
  • System.Management.Automation.dll loaded into a process that is not PowerShell (unmanaged PowerShell).
  • clr.dll loaded into unusual native processes, a sign of in-memory .NET assembly execution.
  • Credential dumping tools loading dbghelp.dll or dbgcore.dll before opening LSASS (event 10).

Investigation tips

  • Check Signed and path of ImageLoaded against the path of Image.
  • Pivot on ProcessGuid to event 1 (parent, command line) and event 10 (process access).
  • Count the hash of ImageLoaded across the fleet; one-off DLLs in common product folders stand out.

MITRE ATT&CK techniques

TechniqueTactics
T1574.001 Hijack Execution Flow: DLLStealth, Execution
T1129 Shared ModulesExecution
T1620 Reflective Code LoadingStealth
T1059.001 Command and Scripting Interpreter: PowerShellExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

99 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 1
  • High · 46
  • Medium · 48
  • Low · 4

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideSysmon Event ID 7: image loads, DLL hijacking and sideloading

Sources and further reading