Windows Process Access to cmlua.dll by CMSTP Connection Manager Profile Installer

Alerts on Windows process access events whose call trace includes cmlua.dll, indicating potential CMSTP-related execution.

FreeReviewedSigma · High · v2
Product
windows
Category
process_access
Author
Nik Seetharaman (SigmaHQ), DRL 1.1
Published
2018-07-16
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

Identifies process access events where the call trace contains cmlua.dll, indicating CMSTP Connection Manager Profile Installer activity tied to UAC-related behavior. Attackers can use CMSTP-enabled execution paths to run code indirectly and evade user awareness. The rule relies on Windows process access telemetry that includes a call trace string containing cmlua.dll.

Related detections9 linkedT1218.003 — drag to rearrange
CMSTP Execution of an INF Profile (via process_creation)
Suspicious CMSTP Execution With INF Payload via process_creation
CMSTP UAC Bypass via Automatic Install Flag (via process_creation)
Windows: cmstp.exe Loading DLL/OCX from Suspicious Paths
Windows Network Connection from Cmstp.EXE (Outbound)
Windows Dllhost.exe Network Connections to Non-Local IP Addresses
Windows DNS Queries Initiated by Regsvr32.exe
Windows Regsvr32.exe Initiated Network Connection
Windows: Command-line execution of cmstp.exe with INF install/silent/autobind flags (UAC bypass pattern)
Windows Process Access to cmlua.dll by CMSTP Connection Manager Profile Installer
Pivot detection · T1218.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.