1200KM / detection
T1218.002 Control Panel — Detection Rules
Detection workspace for T1218.002 Control Panel: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Control Panel Items · test · high · {"product":"windows","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0194 Detection of Malicious Control Panel Item Execution via control.exe or Rundll32
AN0558 Analytic 0558
Execution of control.exe or rundll32.exe with parameters pointing to CPL files, especially from non-standard directories or newly created files, followed by suspicious child process execution or registry modifications registering new Control Panel items.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1218.002 simulation workspace
- File Creation · DC0039
- Module Load · DC0016
- Process Creation · DC0032
- Windows Registry Key Creation · DC0056
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.