Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution

Detects DllHost.exe spawning CMSTP-related autoelevate COM objects by matching known Processid values and high/system integrity.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nik Seetharaman, Christian Burkard (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-07-31
Updated
2026-07-30

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation events where the parent process is DllHost.exe with command lines that include specific COM Processid values tied to CMSTP-enabled autoelevate COM objects. UAC bypass techniques matter because they aim to obtain elevated execution without prompting the user. The detection relies on process creation telemetry, focusing on the parent image and parent command-line content plus high/system integrity levels.

Related detections9 linkedT1548.002 — drag to rearrange
Windows: Command-line execution of cmstp.exe with INF install/silent/autobind flags (UAC bypass pattern)
Malicious FodHelper UAC Bypass via ms-settings Shell Command Hijack (via registry_set)
Suspicious Banana RAT UAC Skip Environment Variable in PowerShell
CMSTP Execution of an INF Profile (via process_creation)
Malicious UAC Bypass via sdclt Handler Hijack (via registry_set)
Malicious UAC Bypass via ms-settings Handler Hijack (via registry_set)
Malicious DBatLoader DLL Sideloading via easinvoker.exe Loading netutils.dll (via image_load)
Suspicious dllhost.exe Spawned with CLSID and Anomalous Parent (via process_creation)
Malicious ms-settings DelegateExecute UAC Bypass Registry Change
Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution
Pivot detection · T1548.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.