Cross-source coverage

T1196 / ATT&CK

Control Panel Items

ATT&CK has retired this technique. Rules still tag it; the current id is T1218.002 System Binary Proxy Execution: Control Panel.

1 rule across 1 source.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Windows Control Panel items are utilities that allow users to view and adjust computer settings. Control Panel items are registered executable (.exe) or Control Panel (.cpl) files, the latter are actually renamed dynamic-link library (.dll) files that export a CPlApplet function. Control Panel items can be executed directly from the command line, programmatically via an application programming interface (API) call, or by simply double-clicking the file.

For ease of use, Control Panel items typically include graphical menus available to users after being registered and loaded into the Control Panel.

Adversaries can use Control Panel items as execution payloads to execute arbitrary commands. Malicious Control Panel items can be delivered via Spearphishing Attachment campaigns or executed as part of multi-stage malware. Control Panel items, specifically CPL files, may also bypass application and/or file extension whitelisting.

Tactics
Stealth · Execution
Platforms
Windows
Telemetry

chronicle/detection-rules

1 rule
Detection Severity Format
control_panel_item_execution_detector_sysmon_behavior Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.