Scripting/CommandLine Process Spawned Regsvr32

 Original Source: [Sigma source]
Title: Scripting/CommandLine Process Spawned Regsvr32
Status: test
Description:Detects various command line and scripting engines/processes such as "PowerShell", "Wscript", "Cmd", etc. spawning a "regsvr32" instance.
References:
  -https://web.archive.org/web/20171001085340/https://subt0x10.blogspot.com/2017/04/bypass-application-whitelisting-script.html
  -https://app.any.run/tasks/34221348-072d-4b70-93f3-aa71f6ebecad/
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-26
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith:
      -'\cmd.exe'
      -'\cscript.exe'
      -'\mshta.exe'
      -'\powershell_ise.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\wscript.exe'

    Image|endswith: '\regsvr32.exe'
  filter_main_rpcproxy:
    ParentImage: 'C:\Windows\System32\cmd.exe'
    CommandLine|endswith: ' /s C:\Windows\System32\RpcProxy\RpcProxy.dll'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Legitimate ".bat", ".hta", ".ps1" or ".vbs" scripts leverage legitimately often. Apply additional filter and exclusions as necessary
  -Some legitimate Windows services
Level: medium