Windows regsvr32.exe Silent DLL execution invoking DllRegisterServer from uncommon paths
Alerts on regsvr32.exe /s /e executions of DLLs from potentially suspicious locations that may trigger DllRegisterServer.
- Product
- windows
- Category
- process_creation
- Author
- Andreas Braathen (mnemonic.io), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-10-17
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation where regsvr32.exe is launched with the silent flag (/s) while using export invocation behavior (/e) for a DLL located in uncommon or potentially suspicious locations. Attackers may use this to load and execute a DLL’s DllRegisterServer entry point while suppressing user-visible output. The detection relies on Windows process creation telemetry, matching regsvr32.exe by image/original filename and inspecting the command line and current directory for path and flag patterns.
Reporting behind it
- thedfirreport.comhttps://thedfirreport.com/2023/08/28/html-smuggling-leads-to-domain-wide-ransomware/
- virustotal.comhttps://www.virustotal.com/gui/file/288fc4f954f98d724e6fab32a89477943df5c0e9662cb199a19b90ae0c63aebe/detection
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/win32/api/olectl/nf-olectl-dllregisterserver
- ss64.comhttps://ss64.com/nt/regsvr32.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_regsvr32_dllregisterserver_exec.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows regsvr32.exe Silent DLL execution invoking DllRegisterServer from uncommon paths
id: 30cc0596-f2e8-4429-ada9-cf7471d0a640
related:
- id: 0ba1da6d-b6ce-4366-828c-18826c9de23e
type: similar
- id: ce2c44b5-a6ac-412a-afba-9e89326fa972
type: derived
status: test
description: This rule flags process creation where regsvr32.exe is launched with the silent flag (/s) while using export invocation behavior (/e) for a DLL located in uncommon or potentially suspicious locations. Attackers may use this to load and execute a DLL’s DllRegisterServer entry point while suppressing user-visible output. The detection relies on Windows process creation telemetry, matching regsvr32.exe by image/original filename and inspecting the command line and current directory for path and flag patterns.
references:
- https://thedfirreport.com/2023/08/28/html-smuggling-leads-to-domain-wide-ransomware/
- https://www.virustotal.com/gui/file/288fc4f954f98d724e6fab32a89477943df5c0e9662cb199a19b90ae0c63aebe/detection
- https://learn.microsoft.com/en-us/windows/win32/api/olectl/nf-olectl-dllregisterserver
- https://ss64.com/nt/regsvr32.html
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_regsvr32_dllregisterserver_exec.yml
author: Andreas Braathen (mnemonic.io), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-10-17
tags:
- attack.stealth
- attack.t1218
- detection.threat-hunting
logsource:
category: process_creation
product: windows
detection:
selection_image:
- Image|endswith: \regsvr32.exe
- OriginalFileName: REGSVR32.EXE
selection_cmdline:
CommandLine|contains:
- " /s "
- " /e "
filter_main_paths:
- CommandLine|contains:
- :\Program Files (x86)
- :\Program Files\
- :\Windows\System32\
- :\Windows\SysWOW64\
- CurrentDirectory|contains:
- :\Program Files (x86)
- :\Program Files\
- :\Windows\System32\
- :\Windows\SysWOW64\
filter_main_other_flags:
CommandLine|contains:
- " /i:"
- "/U "
filter_main_rpcproxy:
ParentCommandLine|endswith: :\Windows\System32\RpcProxy\RpcProxy.dll
CommandLine: regsvr32 /s rpcproxy.dll
condition: all of selection_* and not 1 of filter_main_*
falsepositives:
- Legitimate usage as part of application installation, but less likely from e.g. temporary paths.
level: medium
license: DRL-1.1