1200KM / detection
T1218.010 Regsvr32 — Detection Rules
Detection workspace for T1218.010 Regsvr32: 17 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- DNS Query Request By Regsvr32.EXE · test · medium · {"category":"dns_query","product":"windows"}
- Unsigned DLL Loaded by Windows Utility · test · medium · {"product":"windows","category":"image_load"}
- Network Connection Initiated By Regsvr32.EXE · test · medium · {"category":"network_connection","product":"windows"}
- HTML Help HH.EXE Suspicious Child Process · test · high · {"category":"process_creation","product":"windows"}
- Suspicious HH.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Microsoft Office Child Process · test · high · {"category":"process_creation","product":"windows"}
- Potential Regsvr32 Commandline Flag Anomaly · test · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Regsvr32 HTTP IP Pattern · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Regsvr32 HTTP/FTP Pattern · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Regsvr32 Execution From Remote Share · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Child Process Of Regsvr32 · test · high · {"category":"process_creation","product":"windows"}
- Regsvr32 Execution From Potential Suspicious Location · test · medium · {"category":"process_creation","product":"windows"}
- Regsvr32 Execution From Highly Suspicious Location · test · high · {"category":"process_creation","product":"windows"}
- Regsvr32 DLL Execution With Suspicious File Extension · test · high · {"category":"process_creation","product":"windows"}
- Scripting/CommandLine Process Spawned Regsvr32 · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious WMIC Execution Via Office Process · test · high · {"product":"windows","category":"process_creation"}
- Suspicious WmiPrvSE Child Process · test · high · {"product":"windows","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0282 Detection Strategy for System Binary Proxy Execution: Regsvr32
AN0785 Analytic 0785
Detection focuses on identifying anomalous regsvr32.exe executions that deviate from normal administrative or system use. Defenders may observe regsvr32.exe loading scriptlets or DLLs from unusual paths (especially temporary directories or remote URLs), command-line arguments invoking /i or /u with suspicious file references, network connections initiated by regsvr32.exe, and unsigned or untrusted DLLs being loaded shortly after regsvr32.exe invocation. Correlated sequences include regsvr32.exe process creation, module load of DLL/scriptlet, and optional outbound network traffic.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.