Windows regsvr32 Execution from Suspicious DLL Paths
Alerts on regsvr32 runs whose command line references a DLL in highly suspicious Windows directories.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-05-26
- Updated
- 2026-07-30
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process executions of regsvr32 where the command line indicates the target DLL is located in uncommon or high-risk filesystem paths (e.g., Temp, system component subdirectories, or specific spool/Tasks/Tracing locations). Attackers often use regsvr32 to execute code indirectly through COM registration or DLL loading, making path context a useful signal for stealthy execution. The detection relies on process creation telemetry, matching regsvr32 via image/original filename and correlating command-line path substrings while excluding common legitimate directories.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows regsvr32 Execution from Suspicious DLL Paths
id: 0c19ffd2-946c-4ff5-bd25-b99ea1c04776
status: test
description: This rule flags Windows process executions of regsvr32 where the command line indicates the target DLL is located in uncommon or high-risk filesystem paths (e.g., Temp, system component subdirectories, or specific spool/Tasks/Tracing locations). Attackers often use regsvr32 to execute code indirectly through COM registration or DLL loading, making path context a useful signal for stealthy execution. The detection relies on process creation telemetry, matching regsvr32 via image/original filename and correlating command-line path substrings while excluding common legitimate directories.
references:
- Internal Research
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_2.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-05-26
tags:
- attack.stealth
- attack.t1218.010
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \regsvr32.exe
- OriginalFileName: REGSVR32.EXE
selection_path_1:
CommandLine|contains:
- :\PerfLogs\
- :\Temp\
- \Windows\Registration\CRMLog
- \Windows\System32\com\dmp\
- \Windows\System32\FxsTmp\
- \Windows\System32\Microsoft\Crypto\RSA\MachineKeys\
- \Windows\System32\spool\drivers\color\
- \Windows\System32\spool\PRINTERS\
- \Windows\System32\spool\SERVERS\
- \Windows\System32\Tasks_Migrated\
- \Windows\System32\Tasks\Microsoft\Windows\SyncCenter\
- \Windows\SysWOW64\com\dmp\
- \Windows\SysWOW64\FxsTmp\
- \Windows\SysWOW64\Tasks\Microsoft\Windows\PLA\System\
- \Windows\SysWOW64\Tasks\Microsoft\Windows\SyncCenter\
- \Windows\Tasks\
- \Windows\Tracing\
selection_path_2:
CommandLine|contains:
- ' "C:\'
- " C:\\"
- " 'C:\\"
- D:\
selection_exclude_known_dirs:
CommandLine|contains:
- C:\Program Files (x86)\
- C:\Program Files\
- C:\ProgramData\
- C:\Users\
- " C:\\Windows\\"
- ' "C:\Windows\'
- " 'C:\\Windows\\"
filter_main_empty:
CommandLine: ""
filter_main_null:
CommandLine: null
condition: selection_img and (selection_path_1 or (selection_path_2 and not selection_exclude_known_dirs)) and not 1 of filter_main_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: 327ff235-94eb-4f06-b9de-aaee571324be
type: derived