Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0222 — Detecting MMC (.msc) Proxy Execution and Malicious COM Activation
DET0222

Detecting MMC (.msc) Proxy Execution and Malicious COM Activation

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0622 Analytic 0622
Windows

Abuse of mmc.exe to execute non-Microsoft or user-staged .msc files and malicious COM CLSIDs. Behavioral chain: (1) suspicious mmc.exe invocation with /a or -Embedding and non-standard .msc path → (2) COM activation of non-baseline CLSIDs by mmc.exe → (3) mmc.exe loads non-baseline DLLs (user-writable/UNC/unsigned) → (4) optional network/DNS activity from mmc.exe.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=12 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Microsoft-Windows-COM/Operational CLSID activation events where ProcessName=mmc.exe and CLSID not in allowed baseline WinEventLog:Sysmon EventCode=3, 22 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106
[TimeWindow] Correlation window (e.g., 5–10 minutes) tying .msc creation → mmc.exe start → module loads → COM/net activity.
[AllowedMSCList] Set of Microsoft-supplied .msc names/paths allowed in the environment to suppress noise.
[SuspiciousMSCPathRegex] Regex for user-writable and network paths indicating risky .msc staging (Users, AppData, Downloads, Desktop, UNC).
[AllowedCLSIDs] Baseline of CLSIDs expected to be activated by mmc.exe; alert on unknown/new.
[ParentProcessAllowList] Expected parents for mmc.exe (explorer.exe, services) vs. unusual (powershell, wscript, office apps).
[SignedToUnsignedTransition] Flag when signed mmc.exe results in loading unsigned DLLs.
[ExternalIPAllowlist] Approved external ranges/domains to exclude when mmc.exe makes network requests.

Detected Techniques

1

Stealth (1)

Details

MITRE ID
DET0222
STIX ID
x-mitre-detection-strategy--f4560945-d62f-48b6-ae94-dcd93c471c45
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.