Cross-source coverage
T1196 / ATT&CK
Control Panel Items
ATT&CK has retired this technique. Rules still tag it; the current id is T1218.002 System Binary Proxy Execution: Control Panel.
0 rules across 0 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Windows Control Panel items are utilities that allow users to view and adjust computer settings. Control Panel items are registered executable (.exe) or Control Panel (.cpl) files, the latter are actually renamed dynamic-link library (.dll) files that export a CPlApplet function. Control Panel items can be executed directly from the command line, programmatically via an application programming interface (API) call, or by simply double-clicking the file.
For ease of use, Control Panel items typically include graphical menus available to users after being registered and loaded into the Control Panel.
Adversaries can use Control Panel items as execution payloads to execute arbitrary commands. Malicious Control Panel items can be delivered via Spearphishing Attachment campaigns or executed as part of multi-stage malware. Control Panel items, specifically CPL files, may also bypass application and/or file extension whitelisting.
- Platforms
- Windows
- Telemetry
- —
No live rules cover this technique. 1 deprecated rule is hidden.