Windows ProtocolHandler.exe Download via Embedded URL Schemes

Flags ProtocolHandler.exe executions with ftp/http/https URLs that indicate automated downloading on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-07-13
Updated
2026-07-30
title: Windows ProtocolHandler.exe Download via Embedded URL Schemes
id: 0dad0b1e-659b-4ab8-80ca-d3b88ec3ee99
status: test
description: This rule identifies process executions of ProtocolHandler.exe where the command line contains URL schemes (ftp://, http://, or https://), indicating a file download attempt using the ProtocolHandler binary. Attackers can abuse signed Windows components to fetch external content while blending into normal system behavior. The detection relies on Windows process creation telemetry, matching the executable identity and the presence of these URL schemes in the command line.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1218/T1218.md
  - https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_protocolhandler_download.yml
author: frack113, Huntrule Team
date: 2021-07-13
modified: 2023-11-09
tags:
  - attack.stealth
  - attack.t1218
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: \protocolhandler.exe
    - OriginalFileName: ProtocolHandler.exe
  selection_cli:
    CommandLine|contains:
      - ftp://
      - http://
      - https://
  condition: all of selection_*
falsepositives:
  - Unknown
level: medium
license: DRL-1.1
related:
  - id: 104cdb48-a7a8-4ca7-a453-32942c6e5dcb
    type: derived