Dllhost.EXE Initiated Network Connection To Non-Local IP Address — Detection Rule

Detects Dllhost.EXE initiating a network connection to a non-local IP address. Aside from Microsoft own IP range that needs to be excluded. Network communication from Dllhost will depend entirely on the hosted DLL. An initial baseline is recommended before deployment.

Read the full analysis on IntelFusions