Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility. Regsvcs and Regasm are Windows command-line utilities that are used to register .NET [Component Object Model](https://attack.mitre.org/techniques/T1559/001) (COM) assemblies. Both are binaries that may be digitally signed by Microsoft. (Citation: MSDN Regsvcs) (Citation: MSDN Regasm) Both utilities may be used to bypass application control through use of attributes within the binary to specify code that should be run before registration or unregistration: [ComRegisterFunction] or [ComUnregisterFunction] respectively. The code with the registration and unregistration attributes will be executed even if the process is run under insufficient privileges and fails to execute. (Citation: LOLBAS Regsvcs)(Citation: LOLBAS Regasm)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Detecting .NET COM Registration Abuse via Regsvcs/Regasm
is blocked by Execution Prevention
is blocked by Disable or Remove Feature or Program
is blocked by Asset Inventories
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by User-Installed Software
is blocked by Continuous Monitoring
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Memory Protection
is blocked by Input Data Validation
is blocked by Vulnerability Scanning
Impressum Deutsch Englisch