Detection rules › Elastic
Regsvr32 with Unusual Arguments
Identifies unusual instances of Regsvr32 with suspicious keywords or paths in the process command line value. Adversaries may abuse regsvr32.exe to proxy execution of malicious code.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Stealth |
Rule body
[rule]
description = """
Identifies unusual instances of Regsvr32 with suspicious keywords or paths in the process command line value.
Adversaries may abuse regsvr32.exe to proxy execution of malicious code.
"""
id = "5db08297-bf72-49f4-b426-f405c2b01326"
license = "Elastic License v2"
name = "Regsvr32 with Unusual Arguments"
os_list = ["windows"]
version = "1.0.39"
query = '''
process where event.action == "start" and process.name : "regsvr32.exe" and
(
(process.args_count == 2 and process.working_directory : "?:\\" and not process.working_directory : "C:\\") or
process.command_line :
("*.jpg*",
"*.png*",
"*.gif*",
"*.bmp*",
"*.jpeg*",
"*.TIFF*",
"*.tmp*",
"*.dat*",
"*.pdf*",
"*.doc*",
"*.xls*",
"*.ppt*",
"*.txt*",
"* ?:/*/*",
"* ..\\*",
"*DumpStack.log*",
"*:\\Users\\Public\\*",
"*:\\Users\\*\\Documents\\*",
"*:\\Users\\*\\Pictures\\*",
"*:\\Users\\*\\Music\\*",
"*:\\Users\\*\\Pictures\\*",
"*:\\Windows\\Tasks\\*",
"*:\\Windows\\System32\\tasks\\*",
"*\\DavWWWRoot\\*")
) and
not process.args : ("?:\\Program Files (x86)\\*", "?:\\Program Files\\*") and
/* path traversal */
not (process.command_line : "* ..\\*" and process.command_line :"* ..\\*\\*") and
not process.parent.executable : "?:\\Program Files (x86)\\Tencent\\QQPCMgr\\*\\QQPCTray.exe" and
not process.command_line :
("*\\Program Files (x86)\\Tencent\\QQPCMgr\\*.dat*",
"*QQPCMgr*TSWebMon64.dat*",
"*BarTender Suite\\Codejock.DockingPane.x64.v15.3.1.ocx*") and
not process.parent.executable : "?:\\Eaglesoft\\Shared Files\\OcxReg.exe" and
not process.args : ("?:\\windows\\system32\\ChartFX.ClientServer.Data.dll", "?:\\Windows\\SysWOW64\\ChartFX.ClientServer.Data.dll") and
not (process.args : "?:\\Users\\*\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\*\\Microsoft.Teams.AddinLoader.dll" and process.args : "/i:user") and
not (process.args : "..\\*.dll" and process.working_directory : "?:\\Program Files\\LANDesk\\ManagementSuite\\Install Only Files\\") and
not (process.args : "..\\*.dll" and
descendant of
[process where event.action == "start" and
process.executable : ("?:\\Program Files\\LANDesk\\ManagementSuite\\Install Only Files\\LaunchApp.exe",
"?:\\Program Files (x86)\\LANDesk\\ManagementSuite\\Install Only Files\\LaunchApp.exe")]) and
not (process.parent.name : "msiexec.exe" and process.parent.args : "-Embedding") and
not process.parent.executable : "C:\\Program Files\\LANDesk\\ManagementSuite\\Install Only Files\\LaunchApp.exe" and
not (process.executable : "?:\\Users\\*\\AppData\\Local\\Temp\\SSM*.tmp\\REGSVR32.EXE" and process.args : "?:\\WINDOWS\\system32\\*.dll") and
not process.args : ("?:\\Windows\\Microsoft.NET\\*",
"?:\\Windows\\assembly\\NativeImages*",
"?:\\Windows\\Installer\\MSI*",
"?:\\Windows\\system32\\Codejock.DockingPane.*.ocx",
"?:\\windows\\system32\\Msjet35.dll",
"?:\\windows\\system32\\Msrd2x35.dll",
"System.Data.dll", "Atalasoft.*.dll", "DTI.ImageMan.Codecs.Pdf.dll") and
not (process.name : "regsvr32.exe" and process.parent.executable : "C:\\Windows\\SysWOW64\\cmd.exe" and
process.args : ("C:\\Users\\*\\AppData\\Local\\Temp\\is-*.tmp\\QClickV?\\Driver\\QClickV?_x64.ocx",
"(x86)\\eClinicalWorks_Prod\\RegBlg.bat")) and
process.command_line != "regsvr32 DevExpress.Data.v14.1.dll"
'''
min_endpoint_version = "7.15.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0
[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1218"
name = "System Binary Proxy Execution"
reference = "https://attack.mitre.org/techniques/T1218/"
[[threat.technique.subtechnique]]
id = "T1218.010"
name = "Regsvr32"
reference = "https://attack.mitre.org/techniques/T1218/010/"
[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"
[internal]
min_endpoint_version = "7.15.0"
Stages and Predicates
Stage 1: process
process where event.action == "start" and process.name : "regsvr32.exe" and
(
(process.args_count == 2 and process.working_directory : "?:\\" and not process.working_directory : "C:\\") or
process.command_line :
("*.jpg*",
"*.png*",
"*.gif*",
"*.bmp*",
"*.jpeg*",
"*.TIFF*",
"*.tmp*",
"*.dat*",
"*.pdf*",
"*.doc*",
"*.xls*",
"*.ppt*",
"*.txt*",
"* ?:/*/*",
"* ..\\*",
"*DumpStack.log*",
"*:\\Users\\Public\\*",
"*:\\Users\\*\\Documents\\*",
"*:\\Users\\*\\Pictures\\*",
"*:\\Users\\*\\Music\\*",
"*:\\Users\\*\\Pictures\\*",
"*:\\Windows\\Tasks\\*",
"*:\\Windows\\System32\\tasks\\*",
"*\\DavWWWRoot\\*")
) and
not process.args : ("?:\\Program Files (x86)\\*", "?:\\Program Files\\*") and
not (process.command_line : "* ..\\*" and process.command_line :"* ..\\*\\*") and
not process.parent.executable : "?:\\Program Files (x86)\\Tencent\\QQPCMgr\\*\\QQPCTray.exe" and
not process.command_line :
("*\\Program Files (x86)\\Tencent\\QQPCMgr\\*.dat*",
"*QQPCMgr*TSWebMon64.dat*",
"*BarTender Suite\\Codejock.DockingPane.x64.v15.3.1.ocx*") and
not process.parent.executable : "?:\\Eaglesoft\\Shared Files\\OcxReg.exe" and
not process.args : ("?:\\windows\\system32\\ChartFX.ClientServer.Data.dll", "?:\\Windows\\SysWOW64\\ChartFX.ClientServer.Data.dll") and
not (process.args : "?:\\Users\\*\\AppData\\Local\\Microsoft\\TeamsMeetingAddin\\*\\Microsoft.Teams.AddinLoader.dll" and process.args : "/i:user") and
not (process.args : "..\\*.dll" and process.working_directory : "?:\\Program Files\\LANDesk\\ManagementSuite\\Install Only Files\\") and
not (process.args : "..\\*.dll" and
descendant of
[process where event.action == "start" and
process.executable : ("?:\\Program Files\\LANDesk\\ManagementSuite\\Install Only Files\\LaunchApp.exe",
"?:\\Program Files (x86)\\LANDesk\\ManagementSuite\\Install Only Files\\LaunchApp.exe")]) and
not (process.parent.name : "msiexec.exe" and process.parent.args : "-Embedding") and
not process.parent.executable : "C:\\Program Files\\LANDesk\\ManagementSuite\\Install Only Files\\LaunchApp.exe" and
not (process.executable : "?:\\Users\\*\\AppData\\Local\\Temp\\SSM*.tmp\\REGSVR32.EXE" and process.args : "?:\\WINDOWS\\system32\\*.dll") and
not process.args : ("?:\\Windows\\Microsoft.NET\\*",
"?:\\Windows\\assembly\\NativeImages*",
"?:\\Windows\\Installer\\MSI*",
"?:\\Windows\\system32\\Codejock.DockingPane.*.ocx",
"?:\\windows\\system32\\Msjet35.dll",
"?:\\windows\\system32\\Msrd2x35.dll",
"System.Data.dll", "Atalasoft.*.dll", "DTI.ImageMan.Codecs.Pdf.dll") and
not (process.name : "regsvr32.exe" and process.parent.executable : "C:\\Windows\\SysWOW64\\cmd.exe" and
process.args : ("C:\\Users\\*\\AppData\\Local\\Temp\\is-*.tmp\\QClickV?\\Driver\\QClickV?_x64.ocx",
"(x86)\\eClinicalWorks_Prod\\RegBlg.bat")) and
process.command_line != "regsvr32 DevExpress.Data.v14.1.dll"
Exclusions
The rule actively suppresses these predicates.
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
event.action | eq |
| field:"EventType" kind:eq value:"start" |
process.args_count | eq |
| field:"process.args_count" kind:eq value:"2" |
process.command_line | ne |
| field:"CommandLine" kind:ne value:"regsvr32 DevExpress.Data.v14.1.dll" |
process.command_line | wildcard |
| field:"CommandLine" kind:wildcard |
process.name | wildcard |
| field:"process_name" kind:wildcard value:"regsvr32.exe" |
process.working_directory | wildcard |
| field:"CurrentDirectory" kind:wildcard value:"?:\" |