Windows verclsid.exe executes COM object via GUID parameters

Flags verclsid.exe process launches using /S /C COM GUID-style arguments on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Victor Sergeev, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-09
Updated
2026-07-30
title: Windows verclsid.exe executes COM object via GUID parameters
id: 9509bd5a-3a70-4779-9792-104042853adf
status: test
description: This rule identifies process creation where verclsid.exe is launched with command-line arguments indicative of COM object execution using GUID parameters. Attackers can abuse COM instantiation mechanisms to execute components while blending into legitimate Windows behavior. Detection relies on Windows process creation telemetry, matching the verclsid.exe binary name and specific /S /C command-line patterns, and uses a parent-process filter for RuntimeBroker.exe to reduce false positives.
references:
  - https://lolbas-project.github.io/lolbas/Binaries/Verclsid/
  - https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5
  - https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_verclsid_runs_com.yml
author: Victor Sergeev, oscd.community, Huntrule Team
date: 2020-10-09
modified: 2025-10-07
tags:
  - attack.stealth
  - attack.t1218
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: \verclsid.exe
    - OriginalFileName: verclsid.exe
  selection_cli:
    CommandLine|contains|all:
      - /S
      - /C
  filter_main_runtimebroker:
    ParentImage|endswith: C:\Windows\System32\RuntimeBroker.exe
    CommandLine|contains|all:
      - verclsid.exe" /S /C {
      - "} /I {"
  condition: all of selection_* and not 1 of filter_main_*
falsepositives:
  - Unknown
level: medium
license: DRL-1.1
related:
  - id: d06be4b9-8045-428b-a567-740a26d9db25
    type: derived