Windows regsvr32 Execution from Suspicious DLL Paths

Alerts on regsvr32 runs whose command line references a DLL in highly suspicious Windows directories.

FreeUnreviewedSigmahighv1
title: Windows regsvr32 Execution from Suspicious DLL Paths
id: 0c19ffd2-946c-4ff5-bd25-b99ea1c04776
status: test
description: This rule flags Windows process executions of regsvr32 where the command line indicates the target DLL is located in uncommon or high-risk filesystem paths (e.g., Temp, system component subdirectories, or specific spool/Tasks/Tracing locations). Attackers often use regsvr32 to execute code indirectly through COM registration or DLL loading, making path context a useful signal for stealthy execution. The detection relies on process creation telemetry, matching regsvr32 via image/original filename and correlating command-line path substrings while excluding common legitimate directories.
references:
  - Internal Research
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_2.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-05-26
tags:
  - attack.stealth
  - attack.t1218.010
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: \regsvr32.exe
    - OriginalFileName: REGSVR32.EXE
  selection_path_1:
    CommandLine|contains:
      - :\PerfLogs\
      - :\Temp\
      - \Windows\Registration\CRMLog
      - \Windows\System32\com\dmp\
      - \Windows\System32\FxsTmp\
      - \Windows\System32\Microsoft\Crypto\RSA\MachineKeys\
      - \Windows\System32\spool\drivers\color\
      - \Windows\System32\spool\PRINTERS\
      - \Windows\System32\spool\SERVERS\
      - \Windows\System32\Tasks_Migrated\
      - \Windows\System32\Tasks\Microsoft\Windows\SyncCenter\
      - \Windows\SysWOW64\com\dmp\
      - \Windows\SysWOW64\FxsTmp\
      - \Windows\SysWOW64\Tasks\Microsoft\Windows\PLA\System\
      - \Windows\SysWOW64\Tasks\Microsoft\Windows\SyncCenter\
      - \Windows\Tasks\
      - \Windows\Tracing\
  selection_path_2:
    CommandLine|contains:
      - ' "C:\'
      - " C:\\"
      - " 'C:\\"
      - D:\
  selection_exclude_known_dirs:
    CommandLine|contains:
      - C:\Program Files (x86)\
      - C:\Program Files\
      - C:\ProgramData\
      - C:\Users\
      - " C:\\Windows\\"
      - ' "C:\Windows\'
      - " 'C:\\Windows\\"
  filter_main_empty:
    CommandLine: ""
  filter_main_null:
    CommandLine: null
  condition: selection_img and (selection_path_1 or (selection_path_2 and not selection_exclude_known_dirs)) and not 1 of filter_main_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: 327ff235-94eb-4f06-b9de-aaee571324be
    type: derived

What it detects

This rule flags Windows process executions of regsvr32 where the command line indicates the target DLL is located in uncommon or high-risk filesystem paths (e.g., Temp, system component subdirectories, or specific spool/Tasks/Tracing locations). Attackers often use regsvr32 to execute code indirectly through COM registration or DLL loading, making path context a useful signal for stealthy execution. The detection relies on process creation telemetry, matching regsvr32 via image/original filename and correlating command-line path substrings while excluding common legitimate directories.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.