ByteRay CQL Hub
← All queries

LOLBin Regsvr32

This query detects the use of Regsvr32 when it has loaded scrobj.dll.

CQL · Falcon Next-Gen SIEMCopy query
in(#event_simpleName, values=["ProcessRollup2","ProcessBlocked"])
| event_platform=Win
| ImageFileName=/regsvr32.exe/i CommandLine=/scrobj.dll/i CommandLine=/i:/i

Regsvr32.exe – A native Windows tool designed to register DLLs, but frequently misused by attackers to execute remote or local scriptlets (SCT files)—often enabling Application Whitelisting bypass and stealthy code execution.

LOLBAS - Regsvr32.exe

LOLBin_Regsvr32.yml
T1218.010
ByteRay GmbH
Hunting
Endpoint
Insight
2025-08-26
2025-08-26

Get this query running in your SIEM, with someone on call.

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team