BIOC High

Regsvr32 may have run code from an untrusted source

Regsvr32 may be used to run arbitrary code by passing the '/i' parameter. The code may also be hosted on a remote host.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Execution
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Regsvr32 (T1218.010)
Indicator:

Process action type = execution AND target process cmd = * /i:*http* , * /i*scrobj.dll* AND target process name = regsvr32.exe

Preventable: yes