Detection rules › Splunk

DLLRegisterServer Called from Command Line (Windows Event Log)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

Threat actors including SocGhoulish may use explicit calls to DLLRegisterServer in the command line as a technique to register malicious DLLs, often bypassing standard registration methods like regsvr32. This use case detects instances where any process, including those masquerading as legitimate system utilities, explicitly invokes DLLRegisterServer in the command line. While such executions could be part of legitimate software installations or development activities, unexpected executions should be investigated.

MITRE ATT&CK coverage

References

Telemetry coverage

Rule body

id: '27166.49581'
title: DLLRegisterServer Called from Command Line
description: Threat actors including SocGhoulish may use explicit calls to DLLRegisterServer
  in the command line as a technique to register malicious DLLs, often bypassing standard
  registration methods like regsvr32. This use case detects instances where any process,
  including those masquerading as legitimate system utilities, explicitly invokes
  DLLRegisterServer in the command line. While such executions could be part of legitimate
  software installations or development activities, unexpected executions should be
  investigated.
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR
  "<EventID>4688<" OR Type=Process) ".dll" "DLLRegisterServer" | where match(process,
  "(?i)\.dll\"?,DLLRegisterServer") | table _time, host, user, process, process_*,
  parent_process_* | bin span=1s | stats values(*) as * by _time, host '
techniques:
- defense-evasion:system binary proxy execution:rundll32
technique_id:
- T1218.011
data_category:
- Process command-line parameters
- Windows event logs
references:
- https://redcanary.com/blog/lolbins-abuse/

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR "<EventID>4688<" OR Type=Process) ".dll" "DLLRegisterServer"

Stage 2: where

| where match(process, "(?i)\.dll\"?,DLLRegisterServer")

Stage 3: table

| table _time, host, user, process, process_*, parent_process_*

Stage 4: bucket

| bin span=1s

Stage 5: stats

| stats values(*) as * by _time, host

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 4688 corpus 317 (splunk 283, kusto 33, elastic 1)
field:"EventID" kind:eq value:"4688"
processregex_match
  • "(?i).dll\"?,DLLRegisterServer" corpus 3 (splunk 3)
field:"CommandLine" kind:regex_match

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>4688<"
1".dll"
1"DLLRegisterServer"