Sysmon Event ID 7: Image (DLL) loaded
- Event ID
- 7
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 7 means
Sysmon event 7 records a module being mapped into a process: the host process (Image), the loaded file (ImageLoaded), its hashes, version information and signature status.
Logging every module load would produce enormous volume, so the event is off by default and must be targeted. Typical rules watch for specific DLLs loaded by unexpected processes (for example the PowerShell automation DLL loaded outside PowerShell, or dbghelp.dll / dbgcore.dll loaded by a tool that then touches LSASS), and for unsigned DLLs loaded from user-writable folders.
For DLL side-loading, the telltale pattern is a signed legitimate executable running from an unusual folder and loading an unsigned DLL from the same folder.
When it is logged
Sysmon installed with image load monitoring enabled (-l switch or an <ImageLoad> rule in the configuration). Use narrow include rules; logging all loads is very noisy.
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process that loaded the module; pivot to its event 1. |
| Image | Executable of the loading process. |
| ImageLoaded | Full path of the loaded module. |
| OriginalFileName | Internal name of the module from its version resource; reveals renamed DLLs. |
| Hashes | Hashes of the loaded module. |
| Signed | true or false: whether the module is signed. |
| Signature | Signer of the module. |
| SignatureStatus | Validation result of the signature, e.g. Valid. |
| User | Account of the loading process (newer Sysmon versions). |
Common benign sources
- Applications loading their own DLLs from their install folders.
- Security and monitoring products injecting their modules into many processes.
What attackers do that produces it
- DLL side-loading — a signed executable copied to
ProgramDataor%TEMP%loading an unsigned DLL placed next to it. System.Management.Automation.dllloaded into a process that is not PowerShell (unmanaged PowerShell).clr.dllloaded into unusual native processes, a sign of in-memory .NET assembly execution.- Credential dumping tools loading
dbghelp.dllordbgcore.dllbefore opening LSASS (event 10).
Investigation tips
- Check
Signedand path ofImageLoadedagainst the path ofImage. - Pivot on ProcessGuid to event 1 (parent, command line) and event 10 (process access).
- Count the hash of
ImageLoadedacross the fleet; one-off DLLs in common product folders stand out.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
99 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 1
- High · 46
- Medium · 48
- Low · 4
- CriticalPotential DCOM InternetExplorer.Application DLL Hijack - Image LoadRule by Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga, SigmaHQ, DRL 1.1
- HighAbusable DLL Potential Sideloading From Suspicious LocationRule by X__Junior (Nextron Systems), SigmaHQ, DRL 1.1
- HighAruba Network Service Potential DLL SideloadingRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighBaaUpdate.exe Suspicious DLL LoadRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighDiagnostic Library Sdiageng.DLL Loaded By Msdt.EXERule by Greg (rule), SigmaHQ, DRL 1.1
- HighDLL Loaded From Suspicious Location Via Cmspt.EXERule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighDLL Sideloading Of ShellChromeAPI.DLLRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighDotNet CLR DLL Loaded By Scripting ApplicationsRule by omkar72, oscd.community, SigmaHQ, DRL 1.1
- HighFax Service DLL Search Order HijackRule by NVISO, SigmaHQ, DRL 1.1
- HighGAC DLL Loaded Via Office ApplicationsRule by Antonlovesdnb, SigmaHQ, DRL 1.1
- HighHackTool - SharpEvtMute DLL LoadRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - SILENTTRINITY Stager DLL LoadRule by Aleksey Potapov, oscd.community, SigmaHQ, DRL 1.1
- HighLoad Of RstrtMgr.DLL By A Suspicious ProcessRule by Luc Génaux, SigmaHQ, DRL 1.1
- HighMicrosoft Office DLL SideloadRule by Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), SigmaHQ, DRL 1.1
- HighPCRE.NET Package Image LoadRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighPotential appverifUI.DLL SideloadingRule by X__Junior (Nextron Systems), SigmaHQ, DRL 1.1
- HighPotential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXERule by Swachchhanda Shrawan Poudel, SigmaHQ, DRL 1.1
- HighPotential DLL Sideloading Of Non-Existent DLLs From System FoldersRule by Nasreddine Bencherchali (Nextron Systems), SBousseaden, SigmaHQ, DRL 1.1
- HighPotential DLL Sideloading Via comctl32.dllRule by Nasreddine Bencherchali (Nextron Systems), Subhash Popuri (@pbssubhash), SigmaHQ, DRL 1.1
- HighPotential DLL Sideloading Via VMware XferRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighPotential EACore.DLL SideloadingRule by X__Junior (Nextron Systems), SigmaHQ, DRL 1.1
- HighPotential Edputil.DLL SideloadingRule by X__Junior (Nextron Systems), SigmaHQ, DRL 1.1
- HighPotential Iviewers.DLL SideloadingRule by X__Junior (Nextron Systems), SigmaHQ, DRL 1.1
- HighPotential JLI.dll Side-LoadingRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighPotential Mpclient.DLL SideloadingRule by Bhabesh Raj, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.