AN0932
Analytic 0932
Windows
Execution of CMSTP.exe with arguments pointing to suspicious or remote INF/SCT/DLL payloads, optionally followed by outbound network connections to untrusted IPs, process injection via COM interfaces (CMSTPLUA, CMLUAUTIL), registry modifications registering malicious profiles, or creation of suspicious INF/DLL/SCT files prior to execution.
WinEventLog:PowerShell
EventCode=4103, 4104, 4105, 4106
WinEventLog:Sysmon
EventCode=3, 22
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=10
WinEventLog:Sysmon
EventCode=12
WinEventLog:Sysmon
EventCode=13, 14
WinEventLog:Sysmon
EventCode=11
[INFPathRegex]
Regex for identifying suspicious INF files; adjust to suppress known safe profiles
[ExternalIPAllowlist]
Domains or IP ranges allowed for CMSTP network connections
[COMInterfaceGUIDs]
Set of auto-elevated COM interface GUIDs to flag (e.g., CMSTPLUA, CMLUAUTIL)
[RegistryKeyAllowlist]
Known good registry entries for CMSTP profile registration
[TimeWindow]
Correlate CMSTP execution with subsequent network activity or process creation within N seconds