Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0042 — Detection Strategy for T1218.012 Verclsid Abuse
DET0042

Detection Strategy for T1218.012 Verclsid Abuse

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0118 Analytic 0118
Windows

Detects abuse of verclsid.exe to execute COM objects by monitoring process creation, CLSID arguments, DLLs or scriptlet engines loaded into memory, and If the CLSID points to remote SCT/HTA content, verclsid.exe makes outbound connections.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=3, 22
[AllowedCLSIDs] Baseline CLSIDs frequently invoked by verclsid.exe in normal shell extension verification.
[ParentProcessFilter] Unusual parents (e.g., winword.exe, excel.exe) spawning verclsid.exe should be treated as suspicious.
[TimeWindow] Correlation window between verclsid.exe start, module load, and network activity.
[ExternalIPRange] Restrict detection to external IPs not in approved ranges to cut noise.

Detected Techniques

1

Details

MITRE ID
DET0042
STIX ID
x-mitre-detection-strategy--1d738832-3de4-45f0-98e5-ac37642619e8
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.