{"id":"T1218.010","name":"Regsvr32","url":"https://attack.mitre.org/techniques/T1218/010","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0282","stix_id":"x-mitre-detection-strategy--0a931f22-4820-48aa-8051-056da15a6183","name":"Detection Strategy for System Binary Proxy Execution: Regsvr32","url":"https://attack.mitre.org/detectionstrategies/DET0282","analytics":[{"id":"AN0785","stix_id":"x-mitre-analytic--50658b7e-57c5-4e31-b156-1b294574a9f2","name":"Analytic 0785","description":"Detection focuses on identifying anomalous regsvr32.exe executions that deviate from normal administrative or system use. Defenders may observe regsvr32.exe loading scriptlets or DLLs from unusual paths (especially temporary directories or remote URLs), command-line arguments invoking /i or /u with suspicious file references, network connections initiated by regsvr32.exe, and unsigned or untrusted DLLs being loaded shortly after regsvr32.exe invocation. Correlated sequences include regsvr32.exe process creation, module load of DLL/scriptlet, and optional outbound network traffic.","url":"https://attack.mitre.org/detectionstrategies/DET0282#AN0785","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedDLLPaths","description":"Directories where DLL loading via regsvr32.exe is expected (e.g., C:\\Windows\\System32)."},{"field":"ScriptletExtensions","description":"File extensions considered suspicious when executed by regsvr32.exe (e.g., .sct, .ocx)."},{"field":"TimeWindow","description":"Timeframe to correlate regsvr32.exe process creation with subsequent module loads and network connections."},{"field":"ParentProcessWhitelist","description":"Parent processes from which regsvr32.exe is expected (e.g., explorer.exe during legitimate COM object registration)."}],"live":true,"detection_strategies":["DET0282"],"techniques":["T1218.010"]}],"live":true,"version":"1.0","techniques":["T1218.010"]}],"sigma_rules":[{"id":"089fc3d2-71e8-4763-a8a5-c97fbb0a403e","title":"Regsvr32 DLL Execution With Suspicious File Extension","author":"Florian Roth (Nextron Systems), frack113","status":"test","level":"high","date":"2021-11-29","modified":"2025-08-27","description":"Detects the execution of REGSVR32.exe with DLL files masquerading as other files","references":["https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/","https://blog.talosintelligence.com/2021/10/threat-hunting-in-large-datasets-by.html","https://guides.lib.umich.edu/c.php?g=282942&p=1885348","https://harfanglab.io/insidethelab/uac-0057-pressure-ukraine-poland/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_regsvr32_susp_extensions.yml","techniques":["T1218.010"],"cves":[]},{"id":"10152a7b-b566-438f-a33c-390b607d1c8d","title":"Potential EmpireMonkey Activity","author":"Markus Neis, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2019-04-02","modified":"2023-03-09","description":"Detects potential EmpireMonkey APT activity","references":["https://securelist.com/fin7-5-the-infamous-cybercrime-rig-fin7-continues-its-activities/90703/","https://malpedia.caad.fkie.fraunhofer.de/actor/anthropoid_spider"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010","detection.emerging-threats"],"path":"rules-emerging-threats/2019/TA/EmpireMonkey/proc_creation_win_apt_empiremonkey.yml","techniques":["T1218.010"],"cves":[]},{"id":"2dd2c217-bf68-437a-b57c-fe9fd01d5de8","title":"Potentially Suspicious Regsvr32 HTTP IP Pattern","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-01-11","modified":"2023-05-24","description":"Detects regsvr32 execution to download and install DLLs located remotely where the address is an IP address.","references":["https://twitter.com/mrd0x/status/1461041276514623491","https://twitter.com/tccontre18/status/1480950986650832903","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_regsvr32_http_ip_pattern.yml","techniques":["T1218.010"],"cves":[]},{"id":"327ff235-94eb-4f06-b9de-aaee571324be","title":"Regsvr32 Execution From Highly Suspicious Location","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-05-26","modified":null,"description":"Detects execution of regsvr32 where the DLL is located in a highly suspicious locations","references":["Internal Research"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_2.yml","techniques":["T1218.010"],"cves":[]},{"id":"36e037c4-c228-4866-b6a3-48eb292b9955","title":"DNS Query Request By Regsvr32.EXE","author":"Dmitriy Lifanov, oscd.community","status":"test","level":"medium","date":"2019-10-25","modified":"2023-09-18","description":"Detects DNS queries initiated by \"Regsvr32.exe\"","references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.execution","attack.stealth","attack.t1559.001","attack.t1218.010"],"path":"rules/windows/dns_query/dns_query_win_regsvr32_dns_query.yml","techniques":["T1559.001","T1218.010"],"cves":[]},{"id":"438025f9-5856-4663-83f7-52f878a70a50","title":"Suspicious Microsoft Office Child Process","author":"Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io","status":"test","level":"high","date":"2018-04-06","modified":"2023-04-24","description":"Detects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)","references":["https://www.hybrid-analysis.com/sample/465aabe132ccb949e75b8ab9c5bda36d80cf2fd503d52b8bad54e295f28bbc21?environmentId=100","https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html","https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/","https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e","https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml","https://github.com/splunk/security_content/blob/300af51b88ad5d5b27ce4f5f54e4d6e6a3a2c06d/detections/endpoint/office_spawning_control.yml","https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A","https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set","https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml","https://www.vmray.com/analyses/2d2fa29185ad/report/overview.html","https://app.any.run/tasks/c903e9c8-0350-440c-8688-3881b556b8e0/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1047","attack.t1204.002","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_office_susp_child_processes.yml","techniques":["T1047","T1204.002","T1218.010"],"cves":[]},{"id":"52cad028-0ff0-4854-8f67-d25dfcbc78b4","title":"HTML Help HH.EXE Suspicious Child Process","author":"Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious child process of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]},{"id":"6f0947a4-1c5e-4e0d-8ac7-53159b8f23ca","title":"Potentially Suspicious Child Process Of Regsvr32","author":"elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-05-05","modified":"2023-05-26","description":"Detects potentially suspicious child processes of \"regsvr32.exe\".","references":["https://redcanary.com/blog/intelligence-insights-april-2022/","https://www.echotrail.io/insights/search/regsvr32.exe","https://www.ired.team/offensive-security/code-execution/t1117-regsvr32-aka-squiblydoo"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml","techniques":["T1218.010"],"cves":[]},{"id":"867356ee-9352-41c9-a8f2-1be690d78216","title":"Potentially Suspicious Regsvr32 HTTP/FTP Pattern","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2023-05-24","modified":"2023-05-26","description":"Detects regsvr32 execution to download/install/register new DLLs that are hosted on Web or FTP servers.","references":["https://twitter.com/mrd0x/status/1461041276514623491","https://twitter.com/tccontre18/status/1480950986650832903","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml","techniques":["T1218.010"],"cves":[]},{"id":"88a87a10-384b-4ad7-8871-2f9bf9259ce5","title":"Suspicious Regsvr32 Execution From Remote Share","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-10-31","modified":null,"description":"Detects REGSVR32.exe to execute DLL hosted on remote shares","references":["https://thedfirreport.com/2022/10/31/follina-exploit-leads-to-domain-compromise/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_regsvr32_remote_share.yml","techniques":["T1218.010"],"cves":[]},{"id":"8a582fe2-0882-4b89-a82a-da6b2dc32937","title":"Suspicious WmiPrvSE Child Process","author":"Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-08-23","modified":"2023-11-10","description":"Detects suspicious and uncommon child processes of WmiPrvSE","references":["https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/","https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml","https://blog.osarmor.com/319/onenote-attachment-delivers-asyncrat-malware/","https://twitter.com/ForensicITGuy/status/1334734244120309760"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1047","attack.t1204.002","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_wmiprvse_susp_child_processes.yml","techniques":["T1047","T1204.002","T1218.010"],"cves":[]},{"id":"9525dc73-0327-438c-8c04-13c0e037e9da","title":"Regsvr32 Execution From Potential Suspicious Location","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-26","modified":null,"description":"Detects execution of regsvr32 where the DLL is located in a potentially suspicious location.","references":["https://web.archive.org/web/20171001085340/https://subt0x10.blogspot.com/2017/04/bypass-application-whitelisting-script.html","https://app.any.run/tasks/34221348-072d-4b70-93f3-aa71f6ebecad/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml","techniques":["T1218.010"],"cves":[]},{"id":"ab37a6ec-6068-432b-a64e-2c7bf95b1d22","title":"Scripting/CommandLine Process Spawned Regsvr32","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-26","modified":null,"description":"Detects various command line and scripting engines/processes such as \"PowerShell\", \"Wscript\", \"Cmd\", etc. spawning a \"regsvr32\" instance.","references":["https://web.archive.org/web/20171001085340/https://subt0x10.blogspot.com/2017/04/bypass-application-whitelisting-script.html","https://app.any.run/tasks/34221348-072d-4b70-93f3-aa71f6ebecad/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml","techniques":["T1218.010"],"cves":[]},{"id":"b236190c-1c61-41e9-84b3-3fe03f6d76b0","title":"Potential Regsvr32 Commandline Flag Anomaly","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2019-07-13","modified":"2024-03-13","description":"Detects a potential command line flag anomaly related to \"regsvr32\" in which the \"/i\" flag is used without the \"/n\" which should be uncommon.","references":["https://twitter.com/sbousseaden/status/1282441816986484737?s=12"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010"],"path":"rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml","techniques":["T1218.010"],"cves":[]},{"id":"b5de0c9a-6f19-43e0-af4e-55ad01f550af","title":"Unsigned DLL Loaded by Windows Utility","author":"Swachchhanda Shrawan Poudel","status":"test","level":"medium","date":"2024-02-28","modified":"2025-10-07","description":"Detects windows utilities loading an unsigned or untrusted DLL.\nAdversaries often abuse those programs to proxy execution of malicious code.\n","references":["https://www.elastic.co/security-labs/Hunting-for-Suspicious-Windows-Libraries-for-Execution-and-Evasion","https://akhere.hashnode.dev/hunting-unsigned-dlls-using-kql","https://unit42.paloaltonetworks.com/unsigned-dlls/?web_view=true"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.stealth","attack.t1218.011","attack.t1218.010"],"path":"rules/windows/image_load/image_load_susp_unsigned_dll.yml","techniques":["T1218.011","T1218.010"],"cves":[]},{"id":"bd70d3f8-e60e-4d25-89f0-0b5a9cff20e0","title":"Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32","author":"Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2019-10-02","modified":"2023-03-29","description":"Detects potential BlueMushroom DLL loading activity via regsvr32 from AppData Local","references":["https://pbs.twimg.com/media/EF3yLGoWkAEGeLa?format=jpg"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.010","detection.emerging-threats"],"path":"rules-emerging-threats/2019/TA/APC-C-12/proc_creation_win_apt_aptc12_bluemushroom.yml","techniques":["T1218.010"],"cves":[]},{"id":"c7e91a02-d771-4a6d-a700-42587e0b1095","title":"Network Connection Initiated By Regsvr32.EXE","author":"Dmitriy Lifanov, oscd.community","status":"test","level":"medium","date":"2019-10-25","modified":"2023-09-18","description":"Detects a network connection initiated by \"Regsvr32.exe\"","references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.execution","attack.stealth","attack.t1559.001","attack.t1218.010"],"path":"rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml","techniques":["T1559.001","T1218.010"],"cves":[]},{"id":"e1693bc8-7168-4eab-8718-cdcaa68a1738","title":"Suspicious WMIC Execution Via Office Process","author":"Vadim Khrykov, Cyb3rEng","status":"test","level":"high","date":"2021-08-23","modified":"2023-02-14","description":"Office application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).","references":["https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/","https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1204.002","attack.t1047","attack.t1218.010","attack.execution"],"path":"rules/windows/process_creation/proc_creation_win_wmic_susp_execution_via_office_process.yml","techniques":["T1204.002","T1047","T1218.010"],"cves":[]},{"id":"e8a95b5e-c891-46e2-b33a-93937d3abc31","title":"Suspicious HH.EXE Execution","author":"Maxim Pavlunin","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious execution of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_susp_execution.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}