RegAsm.EXE Execution Without CommandLine Flags or Files

Rule Info

Name
RegAsm.EXE Execution Without CommandLine Flags or Files
Author
frack113
Description
Detects the execution of "RegAsm.exe" without a commandline flag or file, which might indicate potential process injection activity. Usually "RegAsm.exe" should point to a dedicated DLL file or call the help with the "/?" flag.
Date
2025-06-04 00:00:00
Modified
None
Id
651f87f7-12db-47f9-84c5-f27b081b94b6
Tags
attack.defense-evasion attack.t1218.009
Type
Community Rule

Rule History

Author
Title
Date
Commit
frack113
Merge PR #4901 from @frack113 - Regasm Without CommandLine
2025-06-11