Windows .cpl Image Loads from Uncommon Paths Indicating Control Panel Abuse
Alerts on Windows loading of .cpl control panel items from uncommon paths instead of standard system directories.
- Product
- windows
- Category
- image_load
- Author
- Anish Bogati (SigmaHQ), DRL 1.1
- Published
- 2024-01-09
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows image load events where system control panel items (.cpl) are loaded from paths not starting with standard Windows directories. Unusual .cpl loading location can indicate DLL sideloading or other abuse intended to execute code via trusted components. It relies on image load telemetry that records the full ImageLoaded path for these .cpl files.
Reporting behind it
- hexacorn.comhttps://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
- hexacorn.comhttps://www.hexacorn.com/blog/2024/01/01/1-little-known-secret-of-hdwwiz-exe/
- github.comhttps://github.com/mhaskar/FsquirtCPLPoC
- securelist.comhttps://securelist.com/sidewinder-apt/114089/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_side_load_cpl_from_non_system_location.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows .cpl Image Loads from Uncommon Paths Indicating Control Panel Abuse
id: d165805e-50dc-4d16-a081-b125f63f83e2
status: test
description: This rule flags Windows image load events where system control panel items (.cpl) are loaded from paths not starting with standard Windows directories. Unusual .cpl loading location can indicate DLL sideloading or other abuse intended to execute code via trusted components. It relies on image load telemetry that records the full ImageLoaded path for these .cpl files.
references:
- https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
- https://www.hexacorn.com/blog/2024/01/01/1-little-known-secret-of-hdwwiz-exe/
- https://github.com/mhaskar/FsquirtCPLPoC
- https://securelist.com/sidewinder-apt/114089/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_side_load_cpl_from_non_system_location.yml
author: Anish Bogati, Huntrule Team
date: 2024-01-09
modified: 2026-02-17
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
product: windows
category: image_load
detection:
selection:
ImageLoaded|endswith:
- \appwiz.cpl
- \bthprops.cpl
- \hdwwiz.cpl
filter_main_legit_location:
ImageLoaded|startswith:
- C:\Windows\Prefetch\
- C:\Windows\System32\
- C:\Windows\SysWOW64\
- C:\Windows\WinSxS\
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
regression_tests_path: regression_data/rules/windows/image_load/image_load_side_load_cpl_from_non_system_location/info.yml
license: DRL-1.1
related:
- id: 2b140a5c-dc02-4bb8-b6b1-8bdb45714cde
type: derived