{"id":"T1546.007","name":"Netsh Helper DLL","url":"https://attack.mitre.org/techniques/T1546/007","tactics":["privilege-escalation","persistence"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0575","stix_id":"x-mitre-detection-strategy--8d407bff-f721-4b74-a593-1e55c14c5263","name":"Detection Strategy for Netsh Helper DLL Persistence via Registry and Child Process Monitoring (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0575","analytics":[{"id":"AN1588","stix_id":"x-mitre-analytic--5ca1b37f-31c9-414b-9a31-9f80f553c44a","name":"Analytic 1588","description":"Detection focuses on monitoring registry modifications under HKLM\\SOFTWARE\\Microsoft\\Netsh that indicate the addition of helper DLLs, followed by anomalous child process activity or module load behavior initiated by netsh.exe. These behaviors are rarely legitimate and may represent an adversary establishing persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0575#AN1588","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines the time window in which correlated registry and execution events are considered suspicious (e.g., within 10 minutes)"},{"field":"NetshChildProcessWhitelist","description":"List of expected or approved child processes spawned by netsh.exe in the enterprise environment"},{"field":"DLLLoadPath","description":"Directory or filename heuristics to distinguish benign DLLs from malicious helper DLLs"}],"live":true,"detection_strategies":["DET0575"],"techniques":["T1546.007"]}],"live":true,"version":"1.0","techniques":["T1546.007"]}],"sigma_rules":[{"id":"56321594-9087-49d9-bf10-524fe8479452","title":"Potential Persistence Via Netsh Helper DLL","author":"Victor Sergeev, oscd.community","status":"test","level":"medium","date":"2019-10-25","modified":"2023-11-28","description":"Detects the execution of netsh with \"add helper\" flag in order to add a custom helper DLL. This technique can be abused to add a malicious helper DLL that can be used as a persistence proxy that gets called when netsh.exe is executed.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.007/T1546.007.md","https://github.com/outflanknl/NetshHelperBeacon","https://web.archive.org/web/20160928212230/https://www.adaptforward.com/2016/09/using-netshell-to-execute-evil-dlls-and-persist-on-a-host/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.007","attack.s0108"],"path":"rules/windows/process_creation/proc_creation_win_netsh_helper_dll_persistence.yml","techniques":["T1546.007"],"cves":[]},{"id":"c2c76b77-32be-4d1f-82c9-7e544bdfe0eb","title":"Potential Suspicious Activity Using SeCEdit","author":"Janantha Marasinghe","status":"test","level":"medium","date":"2022-11-18","modified":"2022-12-30","description":"Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy","references":["https://blueteamops.medium.com/secedit-and-i-know-it-595056dee53d","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/secedit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.discovery","attack.persistence","attack.credential-access","attack.privilege-escalation","attack.execution","attack.stealth","attack.defense-impairment","attack.t1685.001","attack.t1547.001","attack.t1505.005","attack.t1556.002","attack.t1685","attack.t1574.007","attack.t1564.002","attack.t1546.008","attack.t1546.007","attack.t1547.014","attack.t1547.010","attack.t1547.002","attack.t1557","attack.t1082"],"path":"rules/windows/process_creation/proc_creation_win_secedit_execution.yml","techniques":["T1685.001","T1547.001","T1505.005","T1556.002","T1685","T1574.007","T1564.002","T1546.008","T1546.007","T1547.014","T1547.010","T1547.002","T1557","T1082"],"cves":[]},{"id":"c90362e0-2df3-4e61-94fe-b37615814cb1","title":"Potential Persistence Via Netsh Helper DLL - Registry","author":"Anish Bogati","status":"test","level":"medium","date":"2023-11-28","modified":"2025-10-08","description":"Detects changes to the Netsh registry key to add a new DLL value. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper\n","references":["https://www.ired.team/offensive-security/persistence/t1128-netsh-helper-dll","https://pentestlab.blog/2019/10/29/persistence-netsh-helper-dll/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.007"],"path":"rules/windows/registry/registry_set/registry_set_netsh_helper_dll_potential_persistence.yml","techniques":["T1546.007"],"cves":[]},{"id":"e7b18879-676e-4a0e-ae18-27039185a8e7","title":"New Netsh Helper DLL Registered From A Suspicious Location","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-11-28","modified":null,"description":"Detects changes to the Netsh registry key to add a new DLL value that is located on a suspicious location. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper\n","references":["https://www.ired.team/offensive-security/persistence/t1128-netsh-helper-dll","https://pentestlab.blog/2019/10/29/persistence-netsh-helper-dll/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.007"],"path":"rules/windows/registry/registry_set/registry_set_netsh_help_dll_persistence_susp_location.yml","techniques":["T1546.007"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}