Analytics BIOC
Informational
✕
Registration of Uncommon .NET Services and/or Assemblies
Regasm.exe and regsvcs.exe are used to register .NET COM assemblies, which are typically located in specific paths, attackers might leverage that to execute code within a Microsoft signed binary.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Regsvcs/Regasm (T1218.009)
Attacker's goals:
Load untrusted code into a trusted Microsoft context to evade detection.
Investigative actions:
Verify if the loaded dll is known to be malicious. Track down which process dropped the library being loaded. Validate if the actions being done by the regasm.exe process are malicious.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour