# EQL library where

**URL:** <https://discuss.elastic.co/t/eql-library-where/275524>\
**Category:** SIEM\
**Created:** [June 10, 2021, 7:23am UTC](https://discuss.elastic.co/t/eql-library-where/275524 "2021-06-10T07:23:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 10, 2021, 7:23am UTC](https://discuss.elastic.co/t/eql-library-where/275524/1 "2021-06-10T07:23:38Z")

</div>

Hello,

Just noticed an EQL query in [Suspicious RDP ActiveX Client Loaded | Elastic Security Solution [7.13] | Elastic](https://www.elastic.co/guide/en/security/current/suspicious-rdp-activex-client-loaded.html) where a "library where" clause is used. What kind of events contain library? I always though the first word in the EQL queries pointed to the ECS event categories ([ECS Categorization Field: event.category | Elastic Common Schema (ECS) Reference [1.10] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-allowed-values-event-category.html)), but those do not contain library.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [June 12, 2021, 7:57pm UTC](https://discuss.elastic.co/t/eql-library-where/275524/2 "2021-06-12T19:57:22Z")

</div>

Library is like an unofficial event category. Libraries `.dll` are usually affected via a `process` being executed or running. It is only included in rules when you want to to look when a library is being loaded.

Like the following:

- [detection-rules/execution\_suspicious\_image\_load\_wmi\_ms\_office.toml at main · elastic/detection-rules (github.com)](https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_suspicious_image_load_wmi_ms_office.toml)

```auto
library where process.name : ("WINWORD.EXE", "EXCEL.EXE", "POWERPNT.EXE", "MSPUB.EXE", "MSACCESS.EXE") and
  event.action : "load" and
  event.category : "library" and
  dll.name : "wmiutils.dll"

```

- [detection-rules/persistence\_suspicious\_image\_load\_scheduled\_task\_ms\_office.toml at main · elastic/detection-rules (github.com)](https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_image_load_scheduled_task_ms_office.toml)
- [detection-rules/persistence\_local\_scheduled\_task\_scripting.toml at main · elastic/detection-rules (github.com)](https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_local_scheduled_task_scripting.toml)

And they probably didn't make it official, because it would probably been difficult to make a category `library` to work the same for MacOS, Linux, and Windows

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2021, 7:57pm UTC](https://discuss.elastic.co/t/eql-library-where/275524/3 "2021-07-10T19:57:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
