Windows DISM Disable-Feature Online Execution (DismHost/Dism.exe)
Flags Windows DISM/DismHost executions using /Online and /Disable-Feature, a common defense-impairment technique.
FreeUnreviewedSigmamediumv1
windows-dism-disable-feature-online-execution-dismhost-dism-exe-43e32da2
title: Windows DISM Disable-Feature Online Execution (DismHost/Dism.exe)
id: f42949c5-c590-4d63-9325-218b4f7a5306
status: test
description: This rule identifies process creation events where DISM or DISM host is executed with both /Online and /Disable-Feature parameters. Attackers can use DISM to disable Windows features from the running system, potentially weakening security tooling and defensive capabilities. The detection relies on Windows process creation telemetry, matching specific executable names (Dism.exe or DismHost.exe) and required command-line arguments.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md#atomic-test-26---disable-windows-defender-with-dism
- https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_dism_remove.yml
author: frack113, Huntrule Team
date: 2022-01-16
modified: 2022-08-26
tags:
- attack.defense-impairment
- attack.t1685
logsource:
category: process_creation
product: windows
detection:
selection_dismhost:
Image|endswith: \DismHost.exe
ParentCommandLine|contains|all:
- /Online
- /Disable-Feature
selection_dism:
Image|endswith: \Dism.exe
CommandLine|contains|all:
- /Online
- /Disable-Feature
condition: 1 of selection_*
falsepositives:
- Legitimate script
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_dism_remove/info.yml
simulation:
- type: atomic-red-team
name: Disable Windows Defender with DISM
technique: T1562.001
atomic_guid: 871438ac-7d6e-432a-b27d-3e7db69faf58
license: DRL-1.1
related:
- id: 43e32da2-fdd0-4156-90de-50dfd62636f9
type: derived
What it detects
This rule identifies process creation events where DISM or DISM host is executed with both /Online and /Disable-Feature parameters. Attackers can use DISM to disable Windows features from the running system, potentially weakening security tooling and defensive capabilities. The detection relies on Windows process creation telemetry, matching specific executable names (Dism.exe or DismHost.exe) and required command-line arguments.
Known false positives
- Legitimate script
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.