LiveActive security incident?Get immediate response
MITRE ATT&CK® Detection Strategy

DET0191: Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows)

MITRE ATT&CK DET0191: Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows) Detection Strategy details,…

EnterpriseDET0191Detection StrategyObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

DET0191 is a MITRE detection strategy for spotting ClickOnce-based proxy execution on Windows. The business issue is not ClickOnce itself; it is whether trusted Windows deployment behavior can be abused to run code in a way that blends into normal software launch activity. Security leaders should treat this as an endpoint execution and stealth visibility question: can the organization distinguish approved ClickOnce application use from suspicious ClickOnce-launched child processes?

Executive priority

Prioritize this where Windows endpoints rely on self-updating .NET or ClickOnce applications, or where application execution evidence is needed for incident response and audit readiness. The decision point is whether SOC and IR teams have enough endpoint telemetry to reconstruct ClickOnce execution chains, especially activity involving .appref-ms or .application files and child processes of DFSVC.EXE. Without that evidence, investigations may struggle to explain how code executed through a trusted utility.

Technical view

The related ATT&CK technique is T1127.002 ClickOnce, under execution and stealth, for Windows. Defenders should validate behavior-chain visibility around ClickOnce file types, launch sources such as file shares or web pages, DFSVC.EXE execution, and processes spawned beneath it. Because the official detection text for DET0191 is not supplied, teams should avoid assuming a complete analytic exists and instead test whether their endpoint logging can correlate the ClickOnce artifact, DFSVC.EXE, and the resulting application process.

Likely telemetry

  • Windows process creation telemetry, including parent/child relationships involving DFSVC.EXE
  • Command-line and executable path metadata for ClickOnce-launched processes
  • File activity or launch evidence for .appref-ms and .application files
  • Network or file-share access context when ClickOnce applications are installed or run from a web page or file share
  • Endpoint inventory or software allowlist data for legitimate ClickOnce applications

Detection direction

  • Validate detections as a chain, not a single indicator: ClickOnce-related file use followed by DFSVC.EXE activity and downstream child process execution.
  • Baseline legitimate ClickOnce applications to reduce false positives, since ClickOnce is a normal Windows deployment mechanism.
  • Tune for unusual child processes, locations, or launch patterns relative to approved ClickOnce usage, while requiring local environment baselines before escalating.
  • Confirm that process telemetry preserves parent/child lineage; losing DFSVC.EXE context is a likely blind spot.
  • Use the relationship to T1127.002 as the analytic scope; do not generalize coverage to all trusted developer utility proxy execution techniques without additional validation.

Mitigation priorities

  • Inventory approved ClickOnce applications and business owners before applying restrictive controls.
  • Where ClickOnce is not required, consider policy or application-control restrictions for ClickOnce file execution and associated application launch paths.
  • Where ClickOnce is required, document expected file sources, update locations, and child process behavior for SOC allowlisting and IR triage.
  • Ensure endpoint logging retention is sufficient to reconstruct ClickOnce execution during investigations.
  • Include ClickOnce execution evidence in control testing and incident response playbooks for Windows environments.
Additional notes and limits

This take is based on the DET0191 detection-strategy object and its relationship to ATT&CK technique T1127.002 ClickOnce. The strongest supported operational cue is the ClickOnce execution chain involving .appref-ms/.application files and DFSVC.EXE launching the application. Local baselining is essential because legitimate ClickOnce use can look similar to suspicious activity at a high level.

The supplied DET0191 object has no official description, no official detection text, no tactics, and no platforms of its own. Windows, execution, stealth, ClickOnce file types, file share or web page launch context, and DFSVC.EXE are derived only from the related T1127.002 technique context. No active exploitation, attribution, impact, or detection coverage is implied.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows)

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1127.002ClickOnceSub-techniqueThis object detects ClickOnce.
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
5906da85b72b3d18...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle5906da85b72b…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    mitre-attackDET0191
    Open source URL
  2. [2]
    mitre-attackDET0191
    Open source URL
  3. [3]
    mitre-attackDET0191
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.