1200KM / simulation
T1218.010 Regsvr32 — Attack Simulation
Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. The Regsvr32.exe binary may also be signed by Microsoft. Malicious usage of Regsvr32.exe may avoid triggering security tools that may not monitor execution of, and modules loaded by, the regsvr32.exe…
Technique description
Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. The Regsvr32.exe binary may also be signed by Microsoft. Malicious usage of Regsvr32.exe may avoid triggering security tools that may not monitor execution of, and modules loaded by, the regsvr32.exe…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Regsvr32 local DLL execution
Procedure 08ffca73-9a3d-471a-aeb0-68b4aa3ab37b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Regsvr32 Registering Non DLL
Procedure 1ae5ea1f-0a4e-4e54-b2f5-4ac328a7f421; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Regsvr32 local COM scriptlet execution
Procedure 449aa403-6aba-47ce-8a37-247d21ef0306; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Regsvr32 Silent DLL Install Call DllRegisterServer
Procedure 9d71c492-ea2e-4c08-af16-c6994cdf029f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Regsvr32 remote COM scriptlet execution
Procedure c9d0c4ef-8a96-4794-a75b-3d3a5e6f2a36; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.