Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org
Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs. Netsh.exe (also referred to as Netshell) is a command-line scripting utility used to interact with the network configuration of a system. It contains functionality to add helper DLLs for extending functionality of the utility. The paths to registered netsh.exe helper DLLs are entered into the Windows Registry at HKLM\SOFTWARE\Microsoft\Netsh.
Adversaries can use netsh.exe helper DLLs to trigger execution of arbitrary code in a persistent manner. This execution would take place anytime netsh.exe is executed, which could happen automatically, with another persistence technique, or if other software (ex: VPN) is present on the system that executes netsh.exe as part of its normal functionality.
Rules on DetectionCode tagged with T1546.007.
| Rule | Level | Log source |
|---|---|---|
| New Netsh Helper DLL Registered From A Suspicious Location | high | windows / registry_set |
| Potential Persistence Via Netsh Helper DLL | medium | windows / process_creation |
| Potential Persistence Via Netsh Helper DLL - Registry | medium | windows / registry_set |
| Potential Suspicious Activity Using SeCEdit | medium | windows / process_creation |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.