DET0191: Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows)
MITRE ATT&CK DET0191: Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows) Detection Strategy details,…
Security context for executives and security teams
DET0191 is a MITRE detection strategy for spotting ClickOnce-based proxy execution on Windows. The business issue is not ClickOnce itself; it is whether trusted Windows deployment behavior can be abused to run code in a way that blends into normal software launch activity. Security leaders should treat this as an endpoint execution and stealth visibility question: can the organization distinguish approved ClickOnce application use from suspicious ClickOnce-launched child processes?
Executive priority
Prioritize this where Windows endpoints rely on self-updating .NET or ClickOnce applications, or where application execution evidence is needed for incident response and audit readiness. The decision point is whether SOC and IR teams have enough endpoint telemetry to reconstruct ClickOnce execution chains, especially activity involving .appref-ms or .application files and child processes of DFSVC.EXE. Without that evidence, investigations may struggle to explain how code executed through a trusted utility.
Technical view
The related ATT&CK technique is T1127.002 ClickOnce, under execution and stealth, for Windows. Defenders should validate behavior-chain visibility around ClickOnce file types, launch sources such as file shares or web pages, DFSVC.EXE execution, and processes spawned beneath it. Because the official detection text for DET0191 is not supplied, teams should avoid assuming a complete analytic exists and instead test whether their endpoint logging can correlate the ClickOnce artifact, DFSVC.EXE, and the resulting application process.
Likely telemetry
- Windows process creation telemetry, including parent/child relationships involving DFSVC.EXE
- Command-line and executable path metadata for ClickOnce-launched processes
- File activity or launch evidence for .appref-ms and .application files
- Network or file-share access context when ClickOnce applications are installed or run from a web page or file share
- Endpoint inventory or software allowlist data for legitimate ClickOnce applications
Detection direction
- Validate detections as a chain, not a single indicator: ClickOnce-related file use followed by DFSVC.EXE activity and downstream child process execution.
- Baseline legitimate ClickOnce applications to reduce false positives, since ClickOnce is a normal Windows deployment mechanism.
- Tune for unusual child processes, locations, or launch patterns relative to approved ClickOnce usage, while requiring local environment baselines before escalating.
- Confirm that process telemetry preserves parent/child lineage; losing DFSVC.EXE context is a likely blind spot.
- Use the relationship to T1127.002 as the analytic scope; do not generalize coverage to all trusted developer utility proxy execution techniques without additional validation.
Mitigation priorities
- Inventory approved ClickOnce applications and business owners before applying restrictive controls.
- Where ClickOnce is not required, consider policy or application-control restrictions for ClickOnce file execution and associated application launch paths.
- Where ClickOnce is required, document expected file sources, update locations, and child process behavior for SOC allowlisting and IR triage.
- Ensure endpoint logging retention is sufficient to reconstruct ClickOnce execution during investigations.
- Include ClickOnce execution evidence in control testing and incident response playbooks for Windows environments.
Additional notes and limits
This take is based on the DET0191 detection-strategy object and its relationship to ATT&CK technique T1127.002 ClickOnce. The strongest supported operational cue is the ClickOnce execution chain involving .appref-ms/.application files and DFSVC.EXE launching the application. Local baselining is essential because legitimate ClickOnce use can look similar to suspicious activity at a high level.
The supplied DET0191 object has no official description, no official detection text, no tactics, and no platforms of its own. Windows, execution, stealth, ClickOnce file types, file share or web page launch context, and DFSVC.EXE are derived only from the related T1127.002 technique context. No active exploitation, attribution, impact, or detection coverage is implied.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows)
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.0 | Current bundle | 5906da85b72b… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]mitre-attackDET0191Open source URL
- [2]mitre-attackDET0191Open source URL
- [3]mitre-attackDET0191Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
