CMSTP App Paths Registry Key Modification

 Original Source: [Sigma source]
Title: CMSTP App Paths Registry Key Modification
Status: stable
Description:Detects modifications to the CMSTP App Paths registry key. This may indicate abuse of Microsoft Connection Manager Profile Installer (CMSTP) for arbitrary code execution or UAC bypass.
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Cmstp/
  -https://web.archive.org/web/20190720093911/http://www.endurant.io/cmstp/detecting-cmstp-enabled-code-execution-and-uac-bypass-with-sysmon/
  -https://web.archive.org/web/20190722224110/https://oddvar.moe/2017/08/15/research-on-cmstp-exe/
Author: Nik Seetharaman
Date: 2018-07-16
modified:2026-08-27
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1218.003'
  • -'attack.g0069'
  • -'car.2019-04-001'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
    TargetObject|contains: 'SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe\'
  filter_main_cmcfg32:
    TargetObject|endswith: 'SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe\CmstpExtensionDll'
    Details:
      -'C:\Windows\System32\cmcfg32.dll'
      -'C:\Windows\SysWOW64\cmcfg32.dll'

  filter_main_empty:
    Details: '(Empty)'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Legitimate CMSTP use (unlikely in modern enterprise environments)
Level: high