MMC Executing Files with Reversed Extensions Using RTLO Abuse

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects malicious behavior where the MMC utility (`mmc.exe`) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.

Severity

Critical

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Swachchhanda Shrawan Poudel (Nextron Systems)