Windows regsvr32 Execution from Suspicious DLL Paths

Alerts on regsvr32 runs whose command line references a DLL in highly suspicious Windows directories.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-26
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags Windows process executions of regsvr32 where the command line indicates the target DLL is located in uncommon or high-risk filesystem paths (e.g., Temp, system component subdirectories, or specific spool/Tasks/Tracing locations). Attackers often use regsvr32 to execute code indirectly through COM registration or DLL loading, making path context a useful signal for stealthy execution. The detection relies on process creation telemetry, matching regsvr32 via image/original filename and correlating command-line path substrings while excluding common legitimate directories.

Related detections9 linkedT1218.010 — drag to rearrange
Malicious Regsvr32 ShellExec_RunDLL Proxy Execution (via process_creation)
Suspicious DLL Execution via Regsvr32 DllInstall of dat File
Malicious Xctdoor XcLoader Execution via Regsvr32 AppX Path Abuse (via process_creation)
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Masquerading SSLoad PhantomLoader DLL Execution via Regsvr32 Silent Load from AppData (via process_creation)
Malicious Kimsuky AlphaSeed Payload Execution via Regsvr32 Loading edge dat (via process_creation)
Malicious Regsvr32 Executing DLL From Windows Temp
HttpSpy Payload Registration via Regsvr32 of Non-DLL File (via process_creation)
Malicious regsvr32 Scriptlet Execution via scrobj.dll
Windows regsvr32 Execution from Suspicious DLL Paths
Pivot detection · T1218.010 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.