RegSvr32 Scriptlet Execution¶
Detect regsvr32 loading a script object (scrobj).
id: | 82200c71-f3c3-4b6c-aead-9cafeab602f5 |
---|---|
categories: | detect |
confidence: | medium |
os: | windows |
created: | 11/30/2018 |
updated: | 11/30/2018 |
Query¶
process where subtype.create and
process_name == "regsvr32.exe" and
wildcard(command_line, "*scrobj*", "*/i:*", "*-i:*", "*.sct*")