Windows Process Tree: rundll32.exe launching wermgr.exe via DllRegisterServer

Flags rundll32.exe spawning wermgr.exe where rundll32 command line includes DllRegisterServer.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2020-11-26
Updated
2026-07-31

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a specific Windows process tree pattern where wermgr.exe is spawned by rundll32.exe with the parent command line containing DllRegisterServer. This behavior matters because it indicates executable registration or COM-related activity being used to run a component under a suspicious parent process. The detection relies on process creation telemetry including process image names, parent image names, and parent command-line content.

Related detections2 linkedT1559 — drag to rearrange
Suspicious Named Pipe Pipe2PortCtrl Created by Winnti Malware
Suspicious EastWind Named Pipe Creation
Windows Process Tree: rundll32.exe launching wermgr.exe via DllRegisterServer
Pivot detection · T1559 · 2 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.