Tag
high
advisory
Regasm.exe Process Spawning Detection
2 rules 1 TTPDetection of regasm.exe spawning a child process, an unusual behavior that may indicate attempts to bypass application control and execute arbitrary code.
Windows
living-off-the-land
application-control-bypass
endpoint
2r
1t
medium
advisory
Regasm.exe Making External Network Connection
2 rules 2 TTPsThe detection of regasm.exe, a Microsoft-signed binary, establishing a network connection to a public IP address (excluding private ranges) may indicate command and control activity or attempts to bypass application control.
Microsoft .NET Framework
regasm
application-control-bypass
command-and-control
lolbin
2r
2t