{"id":"T1218.014","name":"MMC","url":"https://attack.mitre.org/techniques/T1218/014","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0222","stix_id":"x-mitre-detection-strategy--f4560945-d62f-48b6-ae94-dcd93c471c45","name":"Detecting MMC (.msc) Proxy Execution and Malicious COM Activation","url":"https://attack.mitre.org/detectionstrategies/DET0222","analytics":[{"id":"AN0622","stix_id":"x-mitre-analytic--e6f38f76-4e60-4b8a-881c-5d3f206e912c","name":"Analytic 0622","description":"Abuse of mmc.exe to execute non-Microsoft or user-staged .msc files and malicious COM CLSIDs. Behavioral chain: (1) suspicious mmc.exe invocation with /a or -Embedding and non-standard .msc path → (2) COM activation of non-baseline CLSIDs by mmc.exe → (3) mmc.exe loads non-baseline DLLs (user-writable/UNC/unsigned) → (4) optional network/DNS activity from mmc.exe.","url":"https://attack.mitre.org/detectionstrategies/DET0222#AN0622","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=12","data_component":"DC0056","data_component_name":"Windows Registry Key Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-COM/Operational","channel":"CLSID activation events where ProcessName=mmc.exe and CLSID not in allowed baseline","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"wineventlog-microsoft-windows-com-operational"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window (e.g., 5–10 minutes) tying .msc creation → mmc.exe start → module loads → COM/net activity."},{"field":"AllowedMSCList","description":"Set of Microsoft-supplied .msc names/paths allowed in the environment to suppress noise."},{"field":"SuspiciousMSCPathRegex","description":"Regex for user-writable and network paths indicating risky .msc staging (Users, AppData, Downloads, Desktop, UNC)."},{"field":"AllowedCLSIDs","description":"Baseline of CLSIDs expected to be activated by mmc.exe; alert on unknown/new."},{"field":"ParentProcessAllowList","description":"Expected parents for mmc.exe (explorer.exe, services) vs. unusual (powershell, wscript, office apps)."},{"field":"SignedToUnsignedTransition","description":"Flag when signed mmc.exe results in loading unsigned DLLs."},{"field":"ExternalIPAllowlist","description":"Approved external ranges/domains to exclude when mmc.exe makes network requests."}],"live":true,"detection_strategies":["DET0222"],"techniques":["T1218.014"]}],"live":true,"version":"1.0","techniques":["T1218.014"]}],"sigma_rules":[{"id":"9cfe4b27-1e56-48b4-b7a8-d46851c91a44","title":"MMC Executing Files with Reversed Extensions Using RTLO Abuse","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-02-05","modified":null,"description":"Detects malicious behavior where the MMC utility (`mmc.exe`) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.","references":["https://www.unicode.org/versions/Unicode5.2.0/ch02.pdf","https://en.wikipedia.org/wiki/Right-to-left_override","https://tria.ge/241015-l98snsyeje/behavioral2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1204.002","attack.t1218.014","attack.t1036.002"],"path":"rules/windows/process_creation/proc_creation_win_mmc_rlo_abuse_pattern.yml","techniques":["T1204.002","T1218.014","T1036.002"],"cves":[]},{"id":"a9c73e8b-3b2d-4c45-8ef2-5f9a9c9998ad","title":"MMC Loading Script Engines DLLs","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-02-05","modified":null,"description":"Detects when the Microsoft Management Console (MMC) loads the DLL libraries like vbscript, jscript etc which might indicate an attempt\nto execute malicious scripts within a trusted system process for bypassing application whitelisting or defense evasion.\n","references":["https://tria.ge/241015-l98snsyeje/behavioral2","https://www.elastic.co/security-labs/grimresource"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.stealth","attack.t1059.005","attack.t1218.014"],"path":"rules/windows/image_load/image_load_win_mmc_loads_script_engine_dll.yml","techniques":["T1059.005","T1218.014"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}