Windows

Regsvr32.exeRegsvr32.exe

Platform
Windows
Abuse functions
6
Mapped techniques
1

Description

Regsvr32.exe is a Windows living-off-the-land binary catalogued by the LOLBAS Project. Documented abuse functions: AWL Bypass, Execute. Mapped ATT&CK techniques (per LOLBAS / GTFOBins → MITRE crosswalk): T1218. Defenders should monitor execution of Regsvr32.exe under non-administrative or sudo contexts and alert when its arguments match the abuse-function signatures.

Abuse functions· 6

AWL BypassT1218.010

Execute code from remote scriptlet, bypass Application whitelisting

AWL BypassT1218.010

Execute code from scriptlet, bypass Application whitelisting

ExecuteT1218.010

Execute code from remote scriptlet, bypass Application whitelisting

ExecuteT1218.010

Execute code from scriptlet, bypass Application whitelisting

ExecuteT1218.010

Execute DLL file

ExecuteT1218.010

Execute DLL file

MITRE ATT&CK techniques· 1

T1218.010

Uses1

TypeTargetConfidenceTier
SubTechniqueRegsvr32t1218.010100%live

Abuses1

TypeTargetConfidenceTier
TechniqueSystem Binary Proxy Executiont121885%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

LOLbin
Regsvcs.exe
LOLbin
Reg.exe
LOLbin
Regasm.exe
LOLbin
Rundll32.exe
LOLbin
Regedit.exe
LOLbin
Shell32.dll
Sourced from LOLBAS Project. Curated by Adam Lundqvist, SQUR.