kevmap

TechniquesT1127.002 › AN0550

AN0550 Analytic 0550

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Abuse of ClickOnce applications where rundll32.exe invokes dfshim.dll with ShOpenVerbApplication or dfsvc.exe spawns unexpected child processes or loads unsigned modules.</p>
Detects
T1127.002 ClickOnce
Part of
DET0191 Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4688DC0032 Process Creation
WinEventLog:SysmonEventCode=7DC0016 Module Load
WinEventLog:Microsoft-Windows-Security-Mitigations/KernelModeETW telemetry indicating ClickOnce deployment (dfsvc.exe) launching payloadsDC0034 Process Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindowThe correlation window for dfsvc.exe/rundll32.exe execution and subsequent module loads or child processes (e.g., 0–10 minutes).
KnownClickOnceAppsWhitelist of legitimate ClickOnce applications and paths.
SuspiciousChildListChild processes considered abnormal when launched by dfsvc.exe or rundll32.exe.