Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0328 — Detection of Malicious Profile Installation via CMSTP.exe
DET0328

Detection of Malicious Profile Installation via CMSTP.exe

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0932 Analytic 0932
Windows

Execution of CMSTP.exe with arguments pointing to suspicious or remote INF/SCT/DLL payloads, optionally followed by outbound network connections to untrusted IPs, process injection via COM interfaces (CMSTPLUA, CMLUAUTIL), registry modifications registering malicious profiles, or creation of suspicious INF/DLL/SCT files prior to execution.

WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=12 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=11
[INFPathRegex] Regex for identifying suspicious INF files; adjust to suppress known safe profiles
[ExternalIPAllowlist] Domains or IP ranges allowed for CMSTP network connections
[COMInterfaceGUIDs] Set of auto-elevated COM interface GUIDs to flag (e.g., CMSTPLUA, CMLUAUTIL)
[RegistryKeyAllowlist] Known good registry entries for CMSTP profile registration
[TimeWindow] Correlate CMSTP execution with subsequent network activity or process creation within N seconds

Detected Techniques

1

Stealth (1)

Details

MITRE ID
DET0328
STIX ID
x-mitre-detection-strategy--c254ecff-c728-4de8-a0f8-e5ad5015aa32
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.