AN0558
Analytic 0558
Windows
Execution of control.exe or rundll32.exe with parameters pointing to CPL files, especially from non-standard directories or newly created files, followed by suspicious child process execution or registry modifications registering new Control Panel items.
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=7
WinEventLog:Sysmon
EventCode=12
[CPLPathRegex]
Regex to match CPL file paths; tune to exclude legitimate CPLs in System32
[ParentProcessName]
Helps filter known parent processes that legitimately use control.exe
[NewFileTimeWindow]
Time delta between CPL file creation and execution to detect rapid execution of newly dropped files
[RegistryKeyAllowlist]
Whitelist of known good CPL registry entries