Title
#general
Hello_There

Hello_There

04/12/2021, 1:24 PM
hi all Is there any way to monitor the use of a dll or the execution of a dll? I am looking to monitor the use or execution of "wininet.dll"
Mike Myers

Mike Myers

04/12/2021, 4:48 PM
Hi. No, currently osquery doesn't have a table that audits DLL load events
Hello_There

Hello_There

04/12/2021, 5:44 PM
glad you for the feedback
w

Will Teller

04/13/2021, 10:40 AM
As Sysmon (ID 7) can log image loads, including DLLs (though can be resource intensive apparently), could not osquery pull-in such event logs?
Mike Myers

Mike Myers

04/13/2021, 3:45 PM
You could use osquery as a log forwarder? Like with
windows_eventlog
table maybe?