Windows Registry: Netsh Helper DLL value added under SOFTWARE\Microsoft\NetSh

Alerts on Windows registry writes under SOFTWARE\Microsoft\NetSh that add .dll helper entries.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Anish Bogati (SigmaHQ), DRL 1.1
Published
2023-11-28
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags registry modifications to the Netsh configuration key by looking for a value containing the .dll extension under SOFTWARE\Microsoft\NetSh. Attackers can use Netsh helper DLLs to load code during normal network configuration activity, providing a persistence mechanism. It relies on registry set telemetry that records the TargetObject and the Details field of the change.

Related detections4 linkedT1546.007 — drag to rearrange
Malicious Netsh Helper DLL Abuse - Process (via process_creation)
Windows: Netsh helper DLL registration via suspicious registry paths
Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Windows netsh.exe "add helper" execution for custom helper DLL loading
Windows Registry: Netsh Helper DLL value added under SOFTWARE\Microsoft\NetSh
Pivot detection · T1546.007 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.