Title:Potential Regsvr32 Commandline Flag Anomaly Status:test Description:Detects a potential command line flag anomaly related to "regsvr32" in which the "/i" flag is used without the "/n" which should be uncommon. References: -https://twitter.com/sbousseaden/status/1282441816986484737?s=12 Author: Florian Roth (Nextron Systems) Date: 2019-07-13 modified:2024-03-13 Tags:
-'attack.stealth'
-'attack.t1218.010'
Logsource:
category: process_creation
product: windows
Detection: selection: Image|endswith:
'\regsvr32.exe' CommandLine|contains|windash:
' -i:' filter_main_flag: CommandLine|contains|windash:
' -n ' condition:selection and not 1 of filter_main_* Falsepositives:
-Administrator typo might cause some false positives Level:medium