Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0194 — Detection of Malicious Control Panel Item Execution via control.exe or Rundll32
DET0194

Detection of Malicious Control Panel Item Execution via control.exe or Rundll32

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0558 Analytic 0558
Windows

Execution of control.exe or rundll32.exe with parameters pointing to CPL files, especially from non-standard directories or newly created files, followed by suspicious child process execution or registry modifications registering new Control Panel items.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=12
[CPLPathRegex] Regex to match CPL file paths; tune to exclude legitimate CPLs in System32
[ParentProcessName] Helps filter known parent processes that legitimately use control.exe
[NewFileTimeWindow] Time delta between CPL file creation and execution to detect rapid execution of newly dropped files
[RegistryKeyAllowlist] Whitelist of known good CPL registry entries

Detected Techniques

1

Details

MITRE ID
DET0194
STIX ID
x-mitre-detection-strategy--012e526a-dacd-4019-a019-bc68733395d2
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.