Regasm/Regsvcs Signed Binary Proxy Execution via Writable Dir or Child Spawn
This rule detects potentially malicious activity involving the Windows binaries Regasm.exe and Regsvcs.exe, which can be abused to proxy the execution of arbitrary code. It specifically identifies three suspicious behaviors: spawning of common command shells or script engines by these binaries, execution of these binaries when located in or loading assemblies from user-writable directories (e.g., Temp, AppData, Downloads), and module loading of DLLs from those same writable locations, especially when the binary is not Microsoft-signed.
SentinelOne

