1200KM / detection
T1218.014 MMC — Detection Rules
Detection workspace for T1218.014 MMC: 2 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- MMC Loading Script Engines DLLs · experimental · medium · {"category":"image_load","product":"windows"}
- MMC Executing Files with Reversed Extensions Using RTLO Abuse · experimental · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0222 Detecting MMC (.msc) Proxy Execution and Malicious COM Activation
AN0622 Analytic 0622
Abuse of mmc.exe to execute non-Microsoft or user-staged .msc files and malicious COM CLSIDs. Behavioral chain: (1) suspicious mmc.exe invocation with /a or -Embedding and non-standard .msc path → (2) COM activation of non-baseline CLSIDs by mmc.exe → (3) mmc.exe loads non-baseline DLLs (user-writable/UNC/unsigned) → (4) optional network/DNS activity from mmc.exe.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1218.014 simulation workspace
- Command Execution · DC0064
- File Creation · DC0039
- Module Load · DC0016
- Network Connection Creation · DC0082
- OS API Execution · DC0021
- Process Creation · DC0032
- Windows Registry Key Creation · DC0056
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.