Detection rules › Splunk
DLLRegisterServer Called from Command Line (Windows Event Log)
Threat actors including SocGhoulish may use explicit calls to DLLRegisterServer in the command line as a technique to register malicious DLLs, often bypassing standard registration methods like regsvr32. This use case detects instances where any process, including those masquerading as legitimate system utilities, explicitly invokes DLLRegisterServer in the command line. While such executions could be part of legitimate software installations or development activities, unexpected executions should be investigated.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Stealth |
References
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Security-Auditing | Event ID 4688: A new process has been created. |
Rule body
id: '27166.49581'
title: DLLRegisterServer Called from Command Line
description: Threat actors including SocGhoulish may use explicit calls to DLLRegisterServer
in the command line as a technique to register malicious DLLs, often bypassing standard
registration methods like regsvr32. This use case detects instances where any process,
including those masquerading as legitimate system utilities, explicitly invokes
DLLRegisterServer in the command line. While such executions could be part of legitimate
software installations or development activities, unexpected executions should be
investigated.
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR
"<EventID>4688<" OR Type=Process) ".dll" "DLLRegisterServer" | where match(process,
"(?i)\.dll\"?,DLLRegisterServer") | table _time, host, user, process, process_*,
parent_process_* | bin span=1s | stats values(*) as * by _time, host '
techniques:
- defense-evasion:system binary proxy execution:rundll32
technique_id:
- T1218.011
data_category:
- Process command-line parameters
- Windows event logs
references:
- https://redcanary.com/blog/lolbins-abuse/
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR "<EventID>4688<" OR Type=Process) ".dll" "DLLRegisterServer"
Stage 2: where
| where match(process, "(?i)\.dll\"?,DLLRegisterServer")
Stage 3: table
| table _time, host, user, process, process_*, parent_process_*
Stage 4: bucket
| bin span=1s
Stage 5: stats
| stats values(*) as * by _time, host
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
EventCode | eq |
| field:"EventID" kind:eq value:"4688" |
process | regex_match |
| field:"CommandLine" kind:regex_match |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | "<EventID>4688<" |
| 1 | ".dll" |
| 1 | "DLLRegisterServer" |