{"id":"T1218.002","name":"Control Panel","url":"https://attack.mitre.org/techniques/T1218/002","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0194","stix_id":"x-mitre-detection-strategy--012e526a-dacd-4019-a019-bc68733395d2","name":"Detection of Malicious Control Panel Item Execution via control.exe or Rundll32","url":"https://attack.mitre.org/detectionstrategies/DET0194","analytics":[{"id":"AN0558","stix_id":"x-mitre-analytic--8581bca4-9d34-4c78-87f7-29244581d140","name":"Analytic 0558","description":"Execution of control.exe or rundll32.exe with parameters pointing to CPL files, especially from non-standard directories or newly created files, followed by suspicious child process execution or registry modifications registering new Control Panel items.","url":"https://attack.mitre.org/detectionstrategies/DET0194#AN0558","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=12","data_component":"DC0056","data_component_name":"Windows Registry Key Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CPLPathRegex","description":"Regex to match CPL file paths; tune to exclude legitimate CPLs in System32"},{"field":"ParentProcessName","description":"Helps filter known parent processes that legitimately use control.exe"},{"field":"NewFileTimeWindow","description":"Time delta between CPL file creation and execution to detect rapid execution of newly dropped files"},{"field":"RegistryKeyAllowlist","description":"Whitelist of known good CPL registry entries"}],"live":true,"detection_strategies":["DET0194"],"techniques":["T1218.002"]}],"live":true,"version":"1.0","techniques":["T1218.002"]}],"sigma_rules":[{"id":"0ba863e6-def5-4e50-9cea-4dd8c7dc46a4","title":"Control Panel Items","author":"Kyaw Min Thein, Furkan Caliskan (@caliskanfurkan_)","status":"test","level":"high","date":"2020-06-22","modified":"2023-10-11","description":"Detects the malicious use of a control panel item","references":["https://ired.team/offensive-security/code-execution/code-execution-through-control-panel-add-ins"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.stealth","attack.t1218.002","attack.persistence","attack.t1546"],"path":"rules/windows/process_creation/proc_creation_win_control_panel_item.yml","techniques":["T1218.002","T1546"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}