LoFP LoFP / t1218.010

t1218.010

TitleTags
administrator typo might cause some false positives
false positives should be limited, filter as needed. in our test case, remcos used regsvr32.exe to modify the registry. it may be required, dependent upon the edr tool producing registry events, to remove (default) from the command-line.
fqdns that start with a number such as \"7-zip\"
legitimate \".bat\", \".hta\", \".ps1\" or \".vbs\" scripts leverage legitimately often. apply additional filter and exclusions as necessary
limited false positives related to third party software registering .dll's.
limited false positives with the query restricted to specified paths. add more world writeable paths as tuning continues.
minimal. but network operator can use this application to load dll.
other third part application may used this parameter but not so common in base windows environment.
some installers might execute \"regsvr32\" with dlls located in %temp% or in %programdata%. apply additional filters if necessary.
some legitimate windows services
unlikely
unlikely, but can rarely occur. apply additional filters accordingly.