Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org
Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility. Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies. Both are binaries that may be digitally signed by Microsoft.
Both utilities may be used to bypass application control through use of attributes within the binary to specify code that should be run before registration or unregistration: [ComRegisterFunction] or [ComUnregisterFunction] respectively. The code with the registration and unregistration attributes will be executed even if the process is run under insufficient privileges and fails to execute.
Rules on DetectionCode tagged with T1218.009.
| Rule | Level | Log source |
|---|---|---|
| Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location | medium | windows / process_creation |
| Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension | medium | windows / process_creation |
| RegAsm.EXE Initiating Network Connection To Public IP | medium | windows / network_connection |
| RegAsm.EXE Execution Without CommandLine Flags or Files | low | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect Regasm Spawning a Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Regasm with Network Connection | TTP | NULL | Sysmon EventID 3 |
| Detect Regasm with no Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Regsvcs Spawning a Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Regsvcs with Network Connection | TTP | NULL | Sysmon EventID 3 |
| Detect Regsvcs with No Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla has dropped RegAsm.exe onto systems for performing malicious activity. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.