dll-unload
March 22, 2023 · View on GitHub
Description
A dll module was unloaded from a process
Parameters
| Parameter | Value |
|---|---|
| Subject | dll |
| Activity | unload |
| Activity Type | dll-unload |
| Pretty Name | Dll Unload |
Fields
The possible fields for this activity type will vary depending on whether the activity was a success or a fail.
dll-unload:success
There are no fields for this activity type.
dll-unload:fail
| Field | Core | Detection | Informational |
|---|---|---|---|
| failure_code | ✓ | ||
| failure_reason | ✓ |