BIOC
High
✕
Regsvr32 may have run code from an untrusted source
Regsvr32 may be used to run arbitrary code by passing the '/i' parameter. The code may also be hosted on a remote host.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Regsvr32 (T1218.010)
Indicator:
Process action type = execution AND target process cmd = * /i:*http* , * /i*scrobj.dll* AND target process name = regsvr32.exe
Preventable: yes