Windows Regsvr32.exe Initiated Network Connection

Flags outbound network connections initiated by Regsvr32.exe based on process image and connection initiation telemetry.

FreeReviewedSigma · Medium · v2
Product
windows
Category
network_connection
Author
Dmitriy Lifanov, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-25
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags when a network connection is initiated by regsvr32.exe on Windows. Attackers may abuse regsvr32 for stealthy execution paths that involve outbound network activity. It relies on network connection telemetry that records the initiating process image name ending with \regsvr32.exe and an initiated connection indicator.

Related detections9 linkedT1218.010 — drag to rearrange
Windows DNS Queries Initiated by Regsvr32.exe
Malicious Regsvr32 Loading Masqueraded VPN DLL via Process Creation
Malicious Regsvr32 ShellExec_RunDLL Proxy Execution (via process_creation)
Suspicious DLL Execution via Regsvr32 DllInstall of dat File
Malicious Xctdoor XcLoader Execution via Regsvr32 AppX Path Abuse (via process_creation)
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Masquerading SSLoad PhantomLoader DLL Execution via Regsvr32 Silent Load from AppData (via process_creation)
Malicious Kimsuky AlphaSeed Payload Execution via Regsvr32 Loading edge dat (via process_creation)
Malicious Regsvr32 Executing DLL From Windows Temp
Windows Regsvr32.exe Initiated Network Connection
Pivot detection · T1218.010 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.