Windows: Netsh helper DLL registration via suspicious registry paths

Flags Netsh helper DLL registration when the DLL path is found in suspicious user/temp-like registry details on Windows.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-11-28
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies registry writes under the NetSh key where a new DLL value is pointed to a location commonly abused for persistence. Attackers may register a Netsh helper DLL stored in user-writable or temporary directories to ensure it is loaded by a trusted Windows component. The detection relies on registry set telemetry capturing the target key path and the DLL location string present in the event details.

Related detections4 linkedT1546.007 — drag to rearrange
Malicious Netsh Helper DLL Abuse - Process (via process_creation)
Windows Registry: Netsh Helper DLL value added under SOFTWARE\Microsoft\NetSh
Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Windows netsh.exe "add helper" execution for custom helper DLL loading
Windows: Netsh helper DLL registration via suspicious registry paths
Pivot detection · T1546.007 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.