Cross-source coverage

T1191 / ATT&CK

CMSTP

ATT&CK has retired this technique. Rules still tag it; the current id is T1218.003 System Binary Proxy Execution: CMSTP.

0 rules across 0 sources.

2 deprecated hidden · include

From MITRE ATT&CK 19.2

The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe accepts an installation information file (INF) as a parameter and installs a service profile leveraged for remote access connections.

Adversaries may supply CMSTP.exe with INF files infected with malicious commands. Similar to Regsvr32 / ”Squiblydoo”, CMSTP.exe may be abused to load and execute DLLs and/or COM scriptlets (SCT) from remote servers. This execution may also bypass AppLocker and other whitelisting defenses since CMSTP.exe is a legitimate, signed Microsoft application.

CMSTP.exe can also be abused to Bypass User Account Control and execute arbitrary commands from a malicious INF through an auto-elevated COM interface.

Tactics
Stealth · Execution
Platforms
Windows
Telemetry

No live rules cover this technique. 2 deprecated rules are hidden.

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.