System Control Panel Item Loaded From Uncommon Location

 Original Source: [Sigma source]
Title: System Control Panel Item Loaded From Uncommon Location
Status: test
Description:Detects image load events of system control panel items (.cpl) from uncommon or non-system locations that may indicate DLL sideloading or other abuse techniques.
References:
  -https://www.hexacorn.com/blog/2024/01/06/1-little-known-secret-of-fondue-exe/
  -https://www.hexacorn.com/blog/2024/01/01/1-little-known-secret-of-hdwwiz-exe/
  -https://github.com/mhaskar/FsquirtCPLPoC
  -https://securelist.com/sidewinder-apt/114089/
Author: Anish Bogati
Date: 2024-01-09
modified:2026-02-17
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • product: windows
  • category: image_load
Detection:
  selection:
    ImageLoaded|endswith:
      -'\appwiz.cpl'
      -'\bthprops.cpl'
      -'\hdwwiz.cpl'

  filter_main_legit_location:
    ImageLoaded|startswith:
      -'C:\Windows\Prefetch\'
      -'C:\Windows\System32\'
      -'C:\Windows\SysWOW64\'
      -'C:\Windows\WinSxS\'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high