Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0282 — Detection Strategy for System Binary Proxy Execution: Regsvr32
DET0282

Detection Strategy for System Binary Proxy Execution: Regsvr32

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0785 Analytic 0785
Windows

Detection focuses on identifying anomalous regsvr32.exe executions that deviate from normal administrative or system use. Defenders may observe regsvr32.exe loading scriptlets or DLLs from unusual paths (especially temporary directories or remote URLs), command-line arguments invoking /i or /u with suspicious file references, network connections initiated by regsvr32.exe, and unsigned or untrusted DLLs being loaded shortly after regsvr32.exe invocation. Correlated sequences include regsvr32.exe process creation, module load of DLL/scriptlet, and optional outbound network traffic.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=3, 22
[AllowedDLLPaths] Directories where DLL loading via regsvr32.exe is expected (e.g., C:\Windows\System32).
[ScriptletExtensions] File extensions considered suspicious when executed by regsvr32.exe (e.g., .sct, .ocx).
[TimeWindow] Timeframe to correlate regsvr32.exe process creation with subsequent module loads and network connections.
[ParentProcessWhitelist] Parent processes from which regsvr32.exe is expected (e.g., explorer.exe during legitimate COM object registration).

Detected Techniques

1

Details

MITRE ID
DET0282
STIX ID
x-mitre-detection-strategy--0a931f22-4820-48aa-8051-056da15a6183
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.