Log source category
registry_event log source Sigma rules
41 Sigma detection rules in the library use the registry_event log source, mostly on windows. The registry_event category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Products
Severity
FlowCloud Registry Markers
criticalDetects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
windows
Leviathan Registry Key Activity
criticalDetects registry key used by Leviathan APT in Malaysian focused campaign
windows
OceanLotus Registry Activity
criticalDetects registry keys created in OceanLotus (also known as APT32) attacks
windows
OilRig APT Registry Persistence
criticalDetects OilRig registry persistence as reported by Nyotron in their March 2018 report
windows
Pandemic Registry Key
criticalDetects Pandemic Windows Implant
windows
Potential Credential Dumping Via LSASS SilentProcessExit Technique
criticalDetects changes to the Registry in which a monitor program gets registered to dump the memory of the lsass.exe process
windows
PrinterNightmare Mimikatz Driver Name
criticalDetects static QMS 810 and mimikatz driver name used by Mimikatz as exploited in CVE-2021-1675 and CVE-2021-34527
windows
Registry Entries For Azorult Malware
criticalDetects the presence of a registry key created during Azorult execution
windows
Sticky Key Like Backdoor Usage - Registry
criticalDetects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen
windows
Windows Credential Editor Registry
criticalDetects the use of Windows Credential Editor (WCE)
windows
CMSTP Execution Registry Event
highDetects various indicators of Microsoft Connection Manager Profile Installer execution
windows
Creation of a Local Hidden User Account by Registry
highSysmon registry detection of a local hidden user account.
windows
Diamond Sleet APT Scheduled Task Creation - Registry
highDetects registry event related to the creation of a scheduled task used by Diamond Sleet APT during exploitation of Team City CVE-2023-42793 vulnerability
windows
Disable Security Events Logging Adding Reg Key MiniNt
highDetects the addition of a key 'MiniNt' to the registry. Upon a reboot, Windows Event Log service will stop writing events.
windows
DLL Load via LSASS
highDetects a method to load DLL via LSASS process using an undocumented Registry key
windows
Esentutl Volume Shadow Copy Service Keys
highDetects the volume shadow copy service initialization and processing via esentutl. Registry keys such as HKLM\\System\\CurrentControlSet\\Services\\VSS\\Diag\\VolSnap\\Volume are captured.
windows
HybridConnectionManager Service Installation - Registry
highDetects the installation of the Azure Hybrid Connection Manager service to allow remote code execution from Azure function.
windows
Narrator's Feedback-Hub Persistence
highDetects abusing Windows 10 Narrator's Feedback-Hub
windows
NetNTLM Downgrade Attack - Registry
highDetects NetNTLM downgrade attack
windows
Potential Qakbot Registry Activity
highDetects a registry key used by IceID in a campaign that distributes malicious OneNote files
windows
RedMimicry Winnti Playbook Registry Manipulation
highDetects actions caused by the RedMimicry Winnti playbook
windows
Registry Persistence Mechanisms in Recycle Bin
highDetects persistence registry keys for Recycle Bin
windows
Security Support Provider (SSP) Added to LSA Configuration
highDetects the addition of a SSP to the registry. Upon a reboot or API call, SSP DLLs gain access to encrypted and plaintext passwords stored in Windows.
windows
Shell Open Registry Keys Manipulation
highDetects the shell open key manipulation (exefile and ms-settings) used for persistence and the pattern of UAC Bypass using fodhelper.exe, computerdefaults.exe, slui.exe via registry keys (e.g. UACMe 33 or 62)
windows
SNAKE Malware Covert Store Registry Key
highDetects any registry event that targets the key 'SECURITY\Policy\Secrets\n' which is a key related to SNAKE malware as described by CISA
windows
Suspicious Camera and Microphone Access
highDetects Processes accessing the camera and microphone from suspicious folder
windows
Suspicious Run Key from Download
highDetects the suspicious RUN keys created by software located in Download or temporary Outlook/Internet Explorer directories
windows
UAC Bypass Via Wsreset
highUnfixed method for UAC bypass from Windows 10. WSReset.exe file associated with the Windows Store. It will run a binary file contained in a low-privilege registry.
windows
Wdigest CredGuard Registry Modification
highDetects potential malicious modification of the property value of IsCredGuardEnabled from HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to disable Cred Guard on a system. This is usually used with UseLogonCredential to manipulate the caching credentials.
windows
Windows Defender Threat Severity Default Action Modified
highDetects modifications or creations of Windows Defender's default threat action settings based on severity to 'allow' or take 'no action'. This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level, allowing malicious software to run unimpeded. An attacker might use this technique to bypass defenses before executing payloads.
windows
WINEKEY Registry Modification
highDetects potential malicious modification of run keys by winekey or team9 backdoor
windows
Atbroker Registry Change
mediumDetects creation/modification of Assistive Technology applications and persistence with usage of 'at'
windows
New DLL Added to AppCertDlls Registry Key
mediumDynamic-link libraries (DLLs) that are specified in the AppCertDLLs value in the Registry key can be abused to obtain persistence and privilege escalation by causing a malicious DLL to be loaded and run in the context of separate processes on the computer.
windows
New DLL Added to AppInit_DLLs Registry Key
mediumDLLs that are specified in the AppInit_DLLs value in the Registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows are loaded by user32.dll into every process that loads user32.dll
windows
New PortProxy Registry Entry Added
mediumDetects the modification of the PortProxy registry key which is used for port forwarding.
windows
Office Application Startup - Office Test
mediumDetects the addition of office test registry that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started
windows
Path To Screensaver Binary Modified
mediumDetects value modification of registry key containing path to binary used as screensaver.
windows
Registry Tampering by Potentially Suspicious Processes
mediumDetects suspicious registry modifications made by suspicious processes such as script engine processes such as WScript, or CScript etc. These processes are rarely used for legitimate registry modifications, and their activity may indicate an attempt to modify the registry without using standard tools like regedit.exe or reg.exe, potentially for evasion and persistence.
windows
Run Once Task Configuration in Registry
mediumRule to detect the configuration of Run Once registry key. Configured payload can be run by runonce.exe /AlternateShellStartup
windows
Windows Registry Trust Record Modification
mediumAlerts on trust record modification within the registry, indicating usage of macros
windows
Scheduled Task Created - Registry
lowDetects the creation of a scheduled task via Registry keys.
windows