
Rule Info
Name
RegAsm.EXE Execution Without CommandLine Flags or Files
Author
frack113
Description
Detects the execution of "RegAsm.exe" without a commandline flag or file, which might indicate potential process injection activity.
Usually "RegAsm.exe" should point to a dedicated DLL file or call the help with the "/?" flag.
Date
2025-06-04 00:00:00
Modified
None
Id
651f87f7-12db-47f9-84c5-f27b081b94b6
Tags
attack.defense-evasion attack.t1218.009
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit