Skip to content
Threat Feed
medium advisory

Abuse of Windows Protocol Handlers for Code Execution

Attackers can exploit custom or native Windows protocol handlers to execute arbitrary commands, maintain persistence, or escalate privileges by abusing URI-based application launching.

Windows protocol handlers are designed to allow applications to register a URI scheme (such as ms-word: or custom application handlers) that launches a specific binary when invoked. Threat actors exploit this mechanism by registering malicious handlers or abusing existing ones to achieve arbitrary code execution. This technique is often categorized under Living off the Land (LotL) activities, as it leverages built-in system functionality to bypass security controls.

Defenders must monitor command-line telemetry for processes spawned in response to protocol handler activation. Because common handlers like http and https are legitimate, high-volume activity is expected, requiring baseline tuning to identify anomalous execution patterns. This technique has been historically associated with various payloads, including malware distribution and remote code execution vulnerabilities. Monitoring for these handlers provides visibility into early-stage delivery or persistence mechanisms.

Attack Chain

  1. Attacker identifies a target application or creates a custom protocol handler entry in the Windows Registry under HKEY_CLASSES_ROOT.
  2. Attacker crafts a malicious URI (e.g., scheme://payload) to be delivered via phishing, malicious documents, or web content.
  3. User clicks the malicious URI link, triggering the system to resolve the handler to a specific executable path.
  4. The operating system shells out to the associated handler binary, passing the crafted URI parameters as command-line arguments.
  5. The handler binary executes, inadvertently processing the attacker-controlled input.
  6. If the handler is vulnerable to command injection, the target process performs unauthorized actions, such as downloading additional payloads or spawning shells.
  7. Final objective is reached, such as gaining initial access, establishing persistence, or achieving privilege escalation via the compromised process context.

Impact

Abuse of protocol handlers can lead to unauthorized code execution, persistence, and privilege escalation on the host. This technique is frequently used in phishing campaigns and remote exploitation scenarios, potentially leading to full system compromise depending on the privileges of the application handling the URI.

Recommendation

Prioritize the identification of abnormal process launches initiated via protocol handler schemes.

  • Ingest Sysmon Event ID 1 or Windows Event ID 4688 logs into your SIEM, ensuring command-line arguments are captured.
  • Map process execution telemetry to the Endpoint data model using the Splunk Common Information Model (CIM) to enable behavioral analytics.
  • Deploy detection logic to flag unusual processes being launched by common browser or office-related protocol handlers.
  • Tune detections by filtering out established legitimate application behavior, such as standard http/https browser launches, to reduce false positives.

Immediate actions

Deploy protocol handler detection logic and tune for benign browser activity

Detection Engineering 48h

Threat Hunt

Search for suspicious process creation events containing '://' in the command line

T1059 high medium confidence hunt now

Data: Process creation logs with command line

Mitigations

Review and remove unused custom URI protocol handlers from the registry

medium_term IT Operations

T1059

Detection coverage 1

Detect Suspicious Protocol Handler Execution

medium

Detects the execution of processes via command line that match known suspicious protocol handler patterns.

sigma tactics: execution techniques: T1059 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →