Suspicious Regsvr32 Squiblydoo Remote Scriptlet Execution via Command Line (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-08-08
Updated
2026-08-28

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects regsvr32.exe launched with the silent registration flags together with a remote scrobj.dll scriptlet reference, the classic Squiblydoo application whitelisting bypass. It is associated with campaigns that deliver regsvr32 execution through malicious Office documents as reported by Uptycs. Attackers use this to run remote COM scriptlets and proxy code execution past application controls, making it a high-value detection.

Related detections9 linkedT1218.010 — drag to rearrange
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Malicious Regsvr32 ShellExec_RunDLL Proxy Execution (via process_creation)
Suspicious DLL Execution via Regsvr32 DllInstall of dat File
Malicious Xctdoor XcLoader Execution via Regsvr32 AppX Path Abuse (via process_creation)
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Masquerading SSLoad PhantomLoader DLL Execution via Regsvr32 Silent Load from AppData (via process_creation)
Malicious Kimsuky AlphaSeed Payload Execution via Regsvr32 Loading edge dat (via process_creation)
Malicious Regsvr32 Executing DLL From Windows Temp
Suspicious Regsvr32 Squiblydoo Remote Scriptlet Execution via Command Line (via process_creation)
Pivot detection · T1218.010 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.