Log source category
registry_set log source Sigma rules
224 Sigma detection rules in the library use the registry_set log source, mostly on windows. The registry_set category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Products
CVE-2021-31979 CVE-2021-33771 Exploits
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows
Add Debugger Entry To Hangs Key For Persistence
highDetects when an attacker adds a new "Debugger" value to the "Hangs" key in order to achieve persistence which will get invoked when an application crashes
windows
AMSI Disabled via Registry Modification
highDetects attempts to disable AMSI (Anti-Malware Scan Interface) by modifying the AmsiEnable registry value. Anti-Malware Scan Interface (AMSI) is a security feature in Windows that allows applications and services to integrate with anti-malware products for enhanced protection against malicious content. Adversaries may attempt to disable AMSI to evade detection by security software, allowing them to execute malicious scripts or code without being scanned.
windows
Antivirus Filter Driver Disallowed On Dev Drive - Registry
highDetects activity that indicates a user disabling the ability for Antivirus mini filter to inspect a "Dev Drive".
windows
Blackbyte Ransomware Registry
highDetects specific windows registry modifications made by BlackByte ransomware variants. BlackByte set three different registry values to escalate privileges and begin setting the stage for lateral movement and encryption. This rule triggers when any of the following registry keys are set to DWORD 1, however all three should be investigated as part of a larger BlackByte ransomware detection and response effort.
windows
Blue Mockingbird - Registry
highAttempts to detect system changes made by Blue Mockingbird
windows
Bypass UAC Using DelegateExecute
highBypasses User Account Control using a fileless method
windows
Bypass UAC Using Event Viewer
highBypasses User Account Control using Event Viewer and a relevant Windows Registry modification
windows
Bypass UAC Using SilentCleanup Task
highDetects the setting of the environement variable "windir" to a non default value. Attackers often abuse this variable in order to trigger a UAC bypass via the "SilentCleanup" task. The SilentCleanup task located in %windir%\system32\cleanmgr.exe is an auto-elevated task that can be abused to elevate any file with administrator privileges without prompting UAC.
windows
Change the Fax Dll
highDetect possible persistence using Fax DLL load when service restart
windows
Change User Account Associated with the FAX Service
highDetect change of the user account associated with the FAX service to avoid the escalation problem.
windows
Change Winevt Channel Access Permission Via Registry
highDetects tampering with the "ChannelAccess" registry key in order to change access to Windows event channel.
windows
COM Hijack via Sdclt
highDetects changes to 'HKCU\Software\Classes\Folder\shell\open\command\DelegateExecute'
windows
COM Object Hijacking Via Modification Of Default System CLSID Default Value
highDetects potential COM object hijacking via modification of default system CLSID.
windows
Custom File Open Handler Executes PowerShell
highDetects the abuse of custom file open handler, executing powershell
windows
CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry
highDetects changes to the "Ports" registry key with data that includes a Windows path or a file with a suspicious extension. This could be an attempt to exploit CVE-2020-1048 - a Windows Print Spooler elevation of privilege vulnerability.
windows
Default RDP Port Changed to Non Standard Port
highDetects changes to the default RDP port. Remote desktop is a common feature in operating systems. It allows a user to log into a remote system using an interactive session with a graphical user interface. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).
windows
DHCP Callout DLL Installation
highDetects the installation of a Callout DLL via CalloutDlls and CalloutEnabled parameter in Registry, which can be used to execute code in context of the DHCP server (restart required)
windows
Directory Service Restore Mode(DSRM) Registry Value Tampering
highDetects changes to "DsrmAdminLogonBehavior" registry value. During a Domain Controller (DC) promotion, administrators create a Directory Services Restore Mode (DSRM) local administrator account with a password that rarely changes. The DSRM account is an “Administrator” account that logs in with the DSRM mode when the server is booting up to restore AD backups or recover the server from a failure. Attackers could abuse DSRM account to maintain their persistence and access to the organization's Active Directory. If the "DsrmAdminLogonBehavior" value is set to "0", the administrator account can only be used if the DC starts in DSRM. If the "DsrmAdminLogonBehavior" value is set to "1", the administrator account can only be used if the local AD DS service is stopped. If the "DsrmAdminLogonBehavior" value is set to "2", the administrator account can always be used.
windows
Disable Macro Runtime Scan Scope
highDetects tampering with the MacroRuntimeScanScope registry key to disable runtime scanning of enabled macros
windows
Disable PUA Protection on Windows Defender
highDetects disabling Windows Defender PUA protection
windows
Disable Windows Defender Functionalities Via Registry Keys
highDetects when attackers or tools disable Windows Defender functionalities via the Windows registry
windows
Disable Windows Event Logging Via Registry
highDetects tampering with the "Enabled" registry key in order to disable Windows logging of a Windows event channel
windows
Disabled Windows Defender Eventlog
highDetects the disabling of the Windows Defender eventlog as seen in relation to Lockbit 3.0 infections
windows
Driver Added To Disallowed Images In HVCI - Registry
highDetects changes to the "HVCIDisallowedImages" registry value to potentially add a driver to the list, in order to prevent it from loading.
windows
Enable LM Hash Storage
highDetects changes to the "NoLMHash" registry value in order to allow Windows to store LM Hashes. By setting this registry value to "0" (DWORD), Windows will be allowed to store a LAN manager hash of your password in Active Directory and local SAM databases.
windows
ETW Logging Disabled In .NET Processes - Sysmon Registry
highPotential adversaries stopping ETW providers recording loaded .NET assemblies.
windows
Execution DLL of Choice Using WAB.EXE
highThis rule detects that the path to the DLL written in the registry is different from the default one. Launched WAB.exe tries to load the DLL from Registry.
windows
FileFix - Command Evidence in TypedPaths
highDetects commonly-used chained commands and strings in the most recent 'url' value of the 'TypedPaths' key, which could be indicative of a user being targeted by the FileFix technique.
windows
Forest Blizzard APT - Custom Protocol Handler Creation
highDetects the setting of a custom protocol handler with the name "rogue". Seen being created by Forest Blizzard APT as reported by MSFT.
windows
Forest Blizzard APT - Custom Protocol Handler DLL Registry Set
highDetects the setting of the DLL that handles the custom protocol handler. Seen being created by Forest Blizzard APT as reported by MSFT.
windows
Hide Schedule Task Via Index Value Tamper
highDetects when the "index" value of a scheduled task is modified from the registry Which effectively hides it from any tooling such as "schtasks /query" (Read the referenced link for more information about the effects of this technique)
windows
Hiding User Account Via SpecialAccounts Registry Key
highDetects modifications to the registry key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\Userlist" where the value is set to "0" in order to hide user account from being listed on the logon screen.
windows
Hypervisor Enforced Paging Translation Disabled
highDetects changes to the "DisableHypervisorEnforcedPagingTranslation" registry value. Where the it is set to "1" in order to disable the Hypervisor Enforced Paging Translation feature.
windows
IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols
highDetects changes to Internet Explorer's (IE / Windows Internet properties) ZoneMap configuration of the "HTTP" and "HTTPS" protocols to point to the "My Computer" zone. This allows downloaded files from the Internet to be granted the same level of trust as files stored locally.
windows
Kapeka Backdoor Autorun Persistence
highDetects the setting of a new value in the Autorun key that is used by the Kapeka backdoor for persistence.
windows
Lolbas OneDriveStandaloneUpdater.exe Proxy Download
highDetects setting a custom URL for OneDriveStandaloneUpdater.exe to download a file from the Internet without executing any anomalous executables with suspicious arguments. The downloaded file will be in C:\Users\redacted\AppData\Local\Microsoft\OneDrive\StandaloneUpdaterreSignInSettingsConfig.json
windows
Lsass Full Dump Request Via DumpType Registry Settings
highDetects the setting of the "DumpType" registry value to "2" which stands for a "Full Dump". Technique such as LSASS Shtinkering requires this value to be "2" in order to dump LSASS.
windows
Macro Enabled In A Potentially Suspicious Document
highDetects registry changes to Office trust records where the path is located in a potentially suspicious location
windows
Microsoft Office Protected View Disabled
highDetects changes to Microsoft Office protected view registry keys with which the attacker disables this feature.
windows
Modify User Shell Folders Startup Value
highDetect modification of the User Shell Folders registry values for Startup or Common Startup which could indicate persistence attempts. Attackers may modify User Shell Folders registry keys to point to malicious executables or scripts that will be executed during startup. This technique is often used to maintain persistence on a compromised system by ensuring that the malicious payload is executed automatically.
windows
NET NGenAssemblyUsageLog Registry Key Tamper
highDetects changes to the NGenAssemblyUsageLog registry key. .NET Usage Log output location can be controlled by setting the NGenAssemblyUsageLog CLR configuration knob in the Registry or by configuring an environment variable (as described in the next section). By simplify specifying an arbitrary value (e.g. fake output location or junk data) for the expected value, a Usage Log file for the .NET execution context will not be created.
windows
New DNS ServerLevelPluginDll Installed
highDetects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
windows
New File Association Using Exefile
highDetects the abuse of the exefile handler in new file association. Used for bypass of security products.
windows
New Netsh Helper DLL Registered From A Suspicious Location
highDetects changes to the Netsh registry key to add a new DLL value that is located on a suspicious location. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper
windows
New RUN Key Pointing to Suspicious Folder
highDetects suspicious new RUN key element pointing to an executable in a suspicious folder
windows
New TimeProviders Registered With Uncommon DLL Name
highDetects processes setting a new DLL in DllName in under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProvider. Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time) enables time synchronization across and within domains.
windows
Office Macros Warning Disabled
highDetects registry changes to Microsoft Office "VBAWarning" to a value of "1" which enables the execution of all macros, whether signed or unsigned.
windows
Outlook EnableUnsafeClientMailRules Setting Enabled - Registry
highDetects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros
windows
Outlook Macro Execution Without Warning Setting Enabled
highDetects the modification of Outlook security setting to allow unprompted execution of macros.
windows
Persistence Via Hhctrl.ocx
highDetects when an attacker modifies the registry value of the "hhctrl" to point to a custom binary
windows
Potential AMSI COM Server Hijacking
highDetects changes to the AMSI come server registry key in order disable AMSI scanning functionalities. When AMSI attempts to starts its COM component, it will query its registered CLSID and return a non-existent COM server. This causes a load failure and prevents any scanning methods from being accessed, ultimately rendering AMSI useless
windows
Potential Attachment Manager Settings Associations Tamper
highDetects tampering with attachment manager settings policies associations to lower the default file type risks (See reference for more information)
windows
Potential Attachment Manager Settings Attachments Tamper
highDetects tampering with attachment manager settings policies attachments (See reference for more information)
windows
Potential AutoLogger Sessions Tampering
highDetects tampering with autologger trace sessions which is a technique used by attackers to disable logging. The AutoLogger event tracing session records events up that occur early in the operating system boot process. Applications and device drivers can use the AutoLogger session to capture traces before the user logs in, and also used by security solutions as telemetry source. Adversaries may disable these sessions to evade detection and prevent security monitoring of early boot activities and system events.
windows
Potential ClickFix Execution Pattern - Registry
highDetects potential ClickFix malware execution patterns by monitoring registry modifications in RunMRU keys containing HTTP/HTTPS links. ClickFix is known to be distributed through phishing campaigns and uses techniques like clipboard hijacking and fake CAPTCHA pages. Through the fakecaptcha pages, the adversary tricks users into opening the Run dialog box and pasting clipboard-hijacked content, such as one-liners that execute remotely hosted malicious files or scripts.
windows
Potential CobaltStrike Service Installations - Registry
highDetects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement.
windows
Potential COLDSTEEL RAT Windows User Creation
highDetects creation of a new user profile with a specific username, seen being used by some variants of the COLDSTEEL RAT.
windows
Potential EventLog File Location Tampering
highDetects tampering with EventLog service "file" key. In order to change the default location of an Evtx file. This technique is used to tamper with log collection and alerting
windows
Potential KamiKakaBot Activity - Winlogon Shell Persistence
highDetects changes to the "Winlogon" registry key where a process will set the value of the "Shell" to a value that was observed being used by KamiKakaBot samples in order to achieve persistence.
windows
Potential Persistence Via App Paths Default Property
highDetects changes to the "Default" property for keys located in the \Software\Microsoft\Windows\CurrentVersion\App Paths\ registry. Which might be used as a method of persistence The entries found under App Paths are used primarily for the following purposes. First, to map an application's executable file name to that file's fully qualified path. Second, to prepend information to the PATH environment variable on a per-application, per-process basis.
windows
Potential Persistence Via AutodialDLL
highDetects change the the "AutodialDLL" key which could be used as a persistence method to load custom DLL via the "ws2_32" library
windows
Potential Persistence Via CHM Helper DLL
highDetects when an attacker modifies the registry key "HtmlHelp Author" to achieve persistence
windows
Potential Persistence Via DLLPathOverride
highDetects when an attacker adds a new "DLLPathOverride" value to the "Natural Language" key in order to achieve persistence which will get invoked by "SearchIndexer.exe" process
windows
Potential Persistence Via Excel Add-in - Registry
highDetect potential persistence via the creation of an excel add-in (XLL) file to make it run automatically when Excel is started.
windows
Potential Persistence Via GlobalFlags
highDetects registry persistence technique using the GlobalFlags and SilentProcessExit keys
windows
Potential Persistence Via LSA Extensions
highDetects when an attacker modifies the "REG_MULTI_SZ" value named "Extensions" to include a custom DLL to achieve persistence via lsass. The "Extensions" list contains filenames of DLLs being automatically loaded by lsass.exe. Each DLL has its InitializeLsaExtension() method called after loading.
windows
Potential Persistence Via Mpnotify
highDetects when an attacker register a new SIP provider for persistence and defense evasion
windows
Potential Persistence Via MyComputer Registry Keys
highDetects modification to the "Default" value of the "MyComputer" key and subkeys to point to a custom binary that will be launched whenever the associated action is executed (see reference section for example)
windows
Potential Persistence Via Outlook Home Page
highDetects potential persistence activity via outlook home page. An attacker can set a home page to achieve code execution and persistence by editing the WebView registry keys.
windows
Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
highDetects the modification of Outlook setting "LoadMacroProviderOnBoot" which if enabled allows the automatic loading of any configured VBA project/module
windows
Potential Persistence Via Outlook Today Page
highDetects potential persistence activity via outlook today page. An attacker can set a custom page to execute arbitrary code and link to it via the registry values "URL" and "UserDefinedUrl".
windows
Potential Persistence Via Shim Database In Uncommon Location
highDetects the installation of a new shim database where the file is located in a non-default location
windows
Potential Persistence Via TypedPaths
highDetects modification addition to the 'TypedPaths' key in the user or admin registry from a non standard application. Which might indicate persistence attempt
windows
Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG
highDetects potential abuse of the provisioning registry key for indirect command execution through "Provlaunch.exe".
windows
Potential PSFactoryBuffer COM Hijacking
highDetects changes to the PSFactory COM InProcServer32 registry. This technique was used by RomCom to create persistence storing a malicious DLL.
windows
Potential Ransomware Activity Using LegalNotice Message
highDetect changes to the "LegalNoticeCaption" or "LegalNoticeText" registry values where the message set contains keywords often used in ransomware ransom messages
windows
Potential Registry Persistence Attempt Via Windows Telemetry
highDetects potential persistence behavior using the windows telemetry registry key. Windows telemetry makes use of the binary CompatTelRunner.exe to run a variety of commands and perform the actual telemetry collections. This binary was created to be easily extensible, and to that end, it relies on the registry to instruct on which commands to run. The problem is, it will run any arbitrary command without restriction of location or type.
windows
Potential Signing Bypass Via Windows Developer Features - Registry
highDetects when the enablement of developer features such as "Developer Mode" or "Application Sideloading". Which allows the user to install untrusted packages.
windows
Potential WerFault ReflectDebugger Registry Value Abuse
highDetects potential WerFault "ReflectDebugger" registry value abuse for persistence.
windows
Potentially Suspicious Command Executed Via Run Dialog Box - Registry
highDetects execution of commands via the run dialog box on Windows by checking values of the "RunMRU" registry key. This technique was seen being abused by threat actors to deceive users into pasting and executing malicious commands, often disguised as CAPTCHA verification steps.
windows
Potentially Suspicious ODBC Driver Registered
highDetects the registration of a new ODBC driver where the driver is located in a potentially suspicious location
windows
PowerShell as a Service in Registry
highDetects that a powershell code is written to the registry as a service.
windows
PowerShell Logging Disabled Via Registry Key Tampering
highDetects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging
windows
Python Function Execution Security Warning Disabled In Excel - Registry
highDetects changes to the registry value "PythonFunctionWarnings" that would prevent any warnings or alerts from showing when Python functions are about to be executed. Threat actors could run malicious code through the new Microsoft Excel feature that allows Python to run within the spreadsheet.
windows
RDP Sensitive Settings Changed
highDetects tampering of RDP Terminal Service/Server sensitive settings. Such as allowing unauthorized users access to a system via the 'fAllowUnsolicited' or enabling RDP via 'fDenyTSConnections', etc. Below is a list of registry keys/values that are monitored by this rule: - Shadow: Used to enable Remote Desktop shadowing, which allows an administrator to view or control a user's session. - DisableRemoteDesktopAntiAlias: Disables anti-aliasing for remote desktop sessions. - DisableSecuritySettings: Disables certain security settings for Remote Desktop connections. - fAllowUnsolicited: Allows unsolicited remote assistance offers. - fAllowUnsolicitedFullControl: Allows unsolicited remote assistance offers with full control. - InitialProgram: Specifies a program to run automatically when a user logs on to a remote computer. - ServiceDll: Used in RDP hijacking techniques to specify a custom DLL to be loaded by the Terminal Services service. - SecurityLayer: Specifies the security layer used for RDP connections.
windows
Registry Disable System Restore
highDetects the modification of the registry to disable a system restore on the computer
windows
Registry Modification for OCI DLL Redirection
highDetects registry modifications related to 'OracleOciLib' and 'OracleOciLibPath' under 'MSDTC' settings. Threat actors may modify these registry keys to redirect the loading of 'oci.dll' to a malicious DLL, facilitating phantom DLL hijacking via the MSDTC service.
windows
Registry Persistence via Explorer Run Key
highDetects a possible persistence mechanism using RUN key for Windows Explorer and pointing to a suspicious folder
windows
Registry Persistence via Service in Safe Mode
highDetects the modification of the registry to allow a driver or service to persist in Safe Mode.
windows
RestrictedAdminMode Registry Value Tampering
highDetects changes to the "DisableRestrictedAdmin" registry value in order to disable or enable RestrictedAdmin mode. RestrictedAdmin mode prevents the transmission of reusable credentials to the remote system to which you connect using Remote Desktop. This prevents your credentials from being harvested during the initial connection process if the remote server has been compromise
windows
Running Chrome VPN Extensions via the Registry 2 VPN Extension
highRunning Chrome VPN Extensions via the Registry install 2 vpn extension
windows
Scheduled TaskCache Change by Uncommon Program
highMonitor the creation of a new key under 'TaskCache' when a new scheduled task is registered by a process that is not svchost.exe, which is suspicious
windows
Security Event Logging Disabled via MiniNt Registry Key - Registry Set
highDetects the addition of the 'MiniNt' key to the registry. Upon a reboot, Windows Event Log service will stop writing events. Windows Event Log is a service that collects and stores event logs from the operating system and applications. It is an important component of Windows security and auditing. Adversary may want to disable this service to disable logging of security events which could be used to detect their activities.
windows
Service Binary in Suspicious Folder
highDetect the creation of a service with a service binary located in a suspicious directory
windows
Small Sieve Malware Registry Persistence
highDetects registry value with specific intentional typo and strings seen used by the Small Sieve malware
windows
Suspicious Application Allowed Through Exploit Guard
highDetects applications being added to the "allowed applications" list of exploit guard in order to bypass controlled folder settings
windows
Suspicious Environment Variable Has Been Registered
highDetects the creation of user-specific or system-wide environment variables via the registry. Which contains suspicious commands and strings
windows
Suspicious Execution Of Renamed Sysinternals Tools - Registry
highDetects the creation of the "accepteula" key related to the Sysinternals tools being created from executables with the wrong name (e.g. a renamed Sysinternals tool)
windows
Suspicious Path In Keyboard Layout IME File Registry Value
highDetects usage of Windows Input Method Editor (IME) keyboard layout feature, which allows an attacker to load a DLL into the process after sending the WM_INPUTLANGCHANGEREQUEST message. Before doing this, the client needs to register the DLL in a special registry key that is assumed to implement this keyboard layout. This registry key should store a value named "Ime File" with a DLL path. IMEs are essential for languages that have more characters than can be represented on a standard keyboard, such as Chinese, Japanese, and Korean.
windows
Suspicious Printer Driver Empty Manufacturer
highDetects a suspicious printer driver installation with an empty Manufacturer value
windows
Suspicious Shim Database Patching Activity
highDetects installation of new shim databases that try to patch sections of known processes for potential process injection or persistence.
windows
Suspicious Space Characters in RunMRU Registry Path - ClickFix
highDetects the occurrence of numerous space characters in RunMRU registry paths, which may indicate execution via phishing lures using clickfix techniques to hide malicious commands in the Windows Run dialog box from naked eyes.
windows
Suspicious Space Characters in TypedPaths Registry Path - FileFix
highDetects the occurrence of numerous space characters in TypedPaths registry paths, which may indicate execution via phishing lures using file-fix techniques to hide malicious commands.
windows
Sysmon Driver Altitude Change
highDetects changes in Sysmon driver altitude value. If the Sysmon driver is configured to load at an altitude of another registered service, it will fail to load at boot.
windows
Tamper With Sophos AV Registry Keys
highDetects tamper attempts to sophos av functionality via registry key modification
windows
Trust Access Disable For VBApplications
highDetects registry changes to Microsoft Office "AccessVBOM" to a value of "1" which disables trust access for VBA on the victim machine and lets attackers execute malicious macros without any Microsoft Office warnings.
windows
UAC Bypass Abusing Winsat Path Parsing - Registry
highDetects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
windows
UAC Bypass Using Windows Media Player - Registry
highDetects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
windows
UAC Bypass via Event Viewer
highDetects UAC bypass method using Windows event viewer
windows
UAC Bypass via Sdclt
highDetects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)
windows
Uncommon Extension In Keyboard Layout IME File Registry Value
highDetects usage of Windows Input Method Editor (IME) keyboard layout feature, which allows an attacker to load a DLL into the process after sending the WM_INPUTLANGCHANGEREQUEST message. Before doing this, the client needs to register the DLL in a special registry key that is assumed to implement this keyboard layout. This registry key should store a value named "Ime File" with a DLL path. IMEs are essential for languages that have more characters than can be represented on a standard keyboard, such as Chinese, Japanese, and Korean.
windows
Uncommon Microsoft Office Trusted Location Added
highDetects changes to registry keys related to "Trusted Location" of Microsoft Office where the path is set to something uncommon. Attackers might add additional trusted locations to avoid macro security restrictions.
windows
Usage of Renamed Sysinternals Tools - RegistrySet
highDetects non-sysinternals tools setting the "accepteula" key which normally is set on sysinternals tool execution
windows
VBScript Payload Stored in Registry
highDetects VBScript content stored into registry keys as seen being used by UNC2452 group
windows
Wdigest Enable UseLogonCredential
highDetects potential malicious modification of the property value of UseLogonCredential from HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to enable clear-text credentials
windows
Windows Credential Guard Disabled - Registry
highDetects attempts to disable Windows Credential Guard by setting registry values to 0. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Adversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation.
windows
Windows Defender Service Disabled - Registry
highDetects when an attacker or tool disables the Windows Defender service (WinDefend) via the registry
windows
Windows Event Log Access Tampering Via Registry
highDetects changes to the Windows EventLog channel permission values. It focuses on changes to the Security Descriptor Definition Language (SDDL) string, as modifications to these values can restrict access to specific users or groups, potentially aiding in defense evasion by controlling who can view or modify a event log channel. Upon execution, the user shouldn't be able to access the event log channel via the event viewer or via utilities such as "Get-EventLog" or "wevtutil".
windows
Windows Hypervisor Enforced Code Integrity Disabled
highDetects changes to the HypervisorEnforcedCodeIntegrity registry key and the "Enabled" value being set to 0 in order to disable the Hypervisor Enforced Code Integrity feature. This allows an attacker to load unsigned and untrusted code to be run in the kernel
windows
Windows Vulnerable Driver Blocklist Disabled
highDetects when the Windows Vulnerable Driver Blocklist is set to disabled. This setting is crucial for preventing the loading of known vulnerable drivers, and its modification may indicate an attempt to bypass security controls. It is often targeted by threat actors to facilitate the installation of malicious or vulnerable drivers, particularly in scenarios involving Endpoint Detection and Response (EDR) bypass techniques. This rule applies to systems that support the Vulnerable Driver Blocklist feature, including Windows 10 version 1903 and later, and Windows Server 2022 and later. Note that this change will require a reboot to take effect, and this rule only detects the registry modification action.
windows
Winlogon Notify Key Logon Persistence
highAdversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in. Winlogon.exe is a Windows component responsible for actions at logon/logoff as well as the secure attention sequence (SAS) triggered by Ctrl-Alt-Delete.
windows
Activate Suppression of Windows Security Center Notifications
mediumDetect set Notification_Suppress to 1 to disable the Windows security center notification
windows
Add Debugger Entry To AeDebug For Persistence
mediumDetects when an attacker adds a new "Debugger" value to the "AeDebug" key in order to achieve persistence which will get invoked when an application crashes
windows
Add DisallowRun Execution to Registry
mediumDetect set DisallowRun to 1 to prevent user running specific computer program
windows
Add Port Monitor Persistence in Registry
mediumAdversaries may use port monitors to run an attacker supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup.
windows
Allow RDP Remote Assistance Feature
mediumDetect enable rdp feature to allow specific user to rdp connect on the targeted machine
windows
Classes Autorun Keys Modification
mediumDetects modification of Windows Registry Classes keys used for persistence. Adversaries modify these autostart extensibility points (ASEP) to execute malicious code when file types are opened or actions are performed. Various legitimate software also uses these keys. Currently, this rule only filters out known legitimate software paths, thus it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
windows
ClickOnce Trust Prompt Tampering
mediumDetects changes to the ClickOnce trust prompt registry key in order to enable an installation from different locations such as the Internet.
windows
COM Hijacking via TreatAs
mediumDetect modification of TreatAs key to enable "rundll32.exe -sta" command
windows
Common Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
CrashControl CrashDump Disabled
mediumDetects disabling the CrashDump per registry (as used by HermeticWiper)
windows
CurrentControlSet Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
CurrentVersion Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
CurrentVersion NT Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
Disable Administrative Share Creation at Startup
mediumAdministrative shares are hidden network shares created by Microsoft Windows NT operating systems that grant system administrators remote access to every disk volume on a network-connected system
windows
Disable Exploit Guard Network Protection on Windows Defender
mediumDetects disabling Windows Defender Exploit Guard Network Protection
windows
Disable Internal Tools or Feature in Registry
mediumDetects registry modifications that change features of internal Windows tools (malware like Agent Tesla uses this technique)
windows
Disable Microsoft Defender Firewall via Registry
mediumAdversaries may disable or modify system firewalls in order to bypass controls limiting network usage
windows
Disable Privacy Settings Experience in Registry
mediumDetects registry modifications that disable Privacy Settings Experience
windows
Disable Tamper Protection on Windows Defender
mediumDetects disabling Windows Defender Tamper Protection
windows
Disable Windows Firewall by Registry
mediumDetect set EnableFirewall to 0 to disable the Windows firewall
windows
Disable Windows Security Center Notifications
mediumDetect set UseActionCenterExperience to 0 to disable the Windows security center notification
windows
Displaying Hidden Files Feature Disabled
mediumDetects modifications to the "Hidden" and "ShowSuperHidden" explorer registry values in order to disable showing of hidden files and system files. This technique is abused by several malware families to hide their files from normal users.
windows
DNS-over-HTTPS Enabled by Registry
mediumDetects when a user enables DNS-over-HTTPS. This can be used to hide internet activity or be used to hide the process of exfiltrating data. With this enabled organization will lose visibility into data such as query type, response and originating IP that are used to determine bad actors.
windows
Enable Local Manifest Installation With Winget
mediumDetects changes to the AppInstaller (winget) policy. Specifically the activation of the local manifest installation, which allows a user to install new packages via custom manifests.
windows
Enable Microsoft Dynamic Data Exchange
mediumEnable Dynamic Data Exchange protocol (DDE) in all supported editions of Microsoft Word or Excel.
windows
Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback
mediumDetects enabling of the "AllowAnonymousCallback" registry value, which allows a remote connection between computers that do not have a trust relationship.
windows
Enabling COR Profiler Environment Variables
mediumDetects .NET Framework CLR and .NET Core CLR "cor_enable_profiling" and "cor_profiler" variables being set and configured.
windows
IE Change Domain Zone
mediumHides the file extension through modification of the registry
windows
Internet Explorer Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
Internet Explorer DisableFirstRunCustomize Enabled
mediumDetects changes to the Internet Explorer "DisableFirstRunCustomize" value, which prevents Internet Explorer from running the first run wizard the first time a user starts the browser after installing Internet Explorer or Windows.
windows
Kapeka Backdoor Configuration Persistence
mediumDetects registry set activity of a value called "Seed" stored in the "\Cryptography\Providers\" registry key. The Kapeka backdoor leverages this location to register a new SIP provider for backdoor configuration persistence.
windows
Microsoft Office Trusted Location Updated
mediumDetects changes to the registry keys related to "Trusted Location" of Microsoft Office. Attackers might add additional trusted locations to avoid macro security restrictions.
windows
New BgInfo.EXE Custom DB Path Registry Configuration
mediumDetects setting of a new registry database value related to BgInfo configuration. Attackers can for example set this value to save the results of the commands executed by BgInfo in order to exfiltrate information.
windows
New BgInfo.EXE Custom VBScript Registry Configuration
mediumDetects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom VBScript via "BgInfo.exe"
windows
New BgInfo.EXE Custom WMI Query Registry Configuration
mediumDetects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom WMI query via "BgInfo.exe"
windows
New Root or CA or AuthRoot Certificate to Store
mediumDetects the addition of new root, CA or AuthRoot certificates to the Windows registry
windows
Office Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry. Adversaries may modify these keys to execute malicious code when Office files are opened. There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive. Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
windows
Old TLS1.0/TLS1.1 Protocol Version Enabled
mediumDetects applications or users re-enabling old TLS versions by setting the "Enabled" value to "1" for the "Protocols" registry key.
windows
Outlook Security Settings Updated - Registry
mediumDetects changes to the registry values related to outlook security settings
windows
Periodic Backup For System Registry Hives Enabled
mediumDetects the enabling of the "EnablePeriodicBackup" registry value. Once enabled, The OS will backup System registry hives on restarts to the "C:\Windows\System32\config\RegBack" folder. Windows creates a "RegIdleBackup" task to manage subsequent backups. Registry backup was a default behavior on Windows and was disabled as of "Windows 10, version 1803".
windows
Persistence Via Disk Cleanup Handler - Autorun
mediumDetects when an attacker modifies values of the Disk Cleanup Handler in the registry to achieve persistence via autorun. The disk cleanup manager is part of the operating system. It displays the dialog box […] The user has the option of enabling or disabling individual handlers by selecting or clearing their check box in the disk cleanup manager's UI. Although Windows comes with a number of disk cleanup handlers, they aren't designed to handle files produced by other applications. Instead, the disk cleanup manager is designed to be flexible and extensible by enabling any developer to implement and register their own disk cleanup handler. Any developer can extend the available disk cleanup services by implementing and registering a disk cleanup handler.
windows
Persistence Via New SIP Provider
mediumDetects when an attacker register a new SIP provider for persistence and defense evasion
windows
Potential COM Object Hijacking Via TreatAs Subkey - Registry
mediumDetects COM object hijacking via TreatAs subkey
windows
Potential Credential Dumping Attempt Using New NetworkProvider - REG
mediumDetects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
windows
Potential Encrypted Registry Blob Related To SNAKE Malware
mediumDetects the creation of a registry value in the ".wav\OpenWithProgIds" key with an uncommon name. This could be related to SNAKE Malware as reported by CISA
windows
Potential PendingFileRenameOperations Tampering
mediumDetect changes to the "PendingFileRenameOperations" registry key from uncommon or suspicious images locations to stage currently used files for rename or deletion after reboot.
windows
Potential Persistence Using DebugPath
mediumDetects potential persistence using Appx DebugPath
windows
Potential Persistence Via AppCompat RegisterAppRestart Layer
mediumDetects the setting of the REGISTERAPPRESTART compatibility layer on an application. This compatibility layer allows an application to register for restart using the "RegisterApplicationRestart" API. This can be potentially abused as a persistence mechanism.
windows
Potential Persistence Via Custom Protocol Handler
mediumDetects potential persistence activity via the registering of a new custom protocole handlers. While legitimate applications register protocole handlers often times during installation. And attacker can abuse this by setting a custom handler to be used as a persistence mechanism.
windows
Potential Persistence Via Event Viewer Events.asp
mediumDetects potential registry persistence technique using the Event Viewer "Events.asp" technique
windows
Potential Persistence Via Logon Scripts - Registry
mediumDetects creation of "UserInitMprLogonScript" registry value which can be used as a persistence method by malicious actors
windows
Potential Persistence Via Netsh Helper DLL - Registry
mediumDetects changes to the Netsh registry key to add a new DLL value. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper
windows
Potential Persistence Via New AMSI Providers - Registry
mediumDetects when an attacker adds a new AMSI provider via the Windows Registry to bypass AMSI (Antimalware Scan Interface) protections. Attackers may add custom AMSI providers to persist on the system and evade detection by security software that relies on AMSI for scanning scripts and other content. This technique is often used in conjunction with fileless malware and script-based attacks to maintain persistence while avoiding detection.
windows
Potential Persistence Via Scrobj.dll COM Hijacking
mediumDetect use of scrobj.dll as this DLL looks for the ScriptletURL key to get the location of the script to execute
windows
Potential Persistence Via Shim Database Modification
mediumAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time
windows
Potential Persistence Via Visual Studio Tools for Office
mediumDetects persistence via Visual Studio Tools for Office (VSTO) add-ins in Office applications.
windows
Potential PowerShell Execution Policy Tampering
mediumDetects changes to the PowerShell execution policy in order to bypass signing requirements for script execution
windows
Potential Registry Persistence Attempt Via DbgManagedDebugger
mediumDetects the addition of the "Debugger" value to the "DbgManagedDebugger" key in order to achieve persistence. Which will get invoked when an application crashes
windows
Potential SentinelOne Shell Context Menu Scan Command Tampering
mediumDetects potentially suspicious changes to the SentinelOne context menu scan command by a process other than SentinelOne.
windows
Potentially Suspicious Desktop Background Change Via Registry
mediumDetects registry value settings that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
windows
PUA - Sysinternals Tools Execution - Registry
mediumDetects the execution of some potentially unwanted tools such as PsExec, Procdump, etc. (part of the Sysinternals suite) via the creation of the "accepteula" registry key.
windows
RDP Sensitive Settings Changed to Zero
mediumDetects tampering of RDP Terminal Service/Server sensitive settings. Such as allowing unauthorized users access to a system via the 'fAllowUnsolicited' or enabling RDP via 'fDenyTSConnections', etc.
windows
Register New IFiltre For Persistence
mediumDetects when an attacker registers a new IFilter for an extension. Microsoft Windows Search uses filters to extract the content of items for inclusion in a full-text index. You can extend Windows Search to index new or proprietary file types by writing filters to extract the content, and property handlers to extract the properties of files.
windows
Registry Explorer Policy Modification
mediumDetects registry modifications that disable internal tools or functions in explorer (malware like Agent Tesla uses this technique)
windows
Registry Hide Function from User
mediumDetects registry modifications that hide internal tools or functions from the user (malware like Agent Tesla, Hermetic Wiper uses this technique)
windows
Registry Modification to Hidden File Extension
mediumHides the file extension through modification of the registry
windows
Registry Set With Crypto-Classes From The "Cryptography" PowerShell Namespace
mediumDetects the setting of a registry inside the "\Shell\Open\Command" value with PowerShell classes from the "System.Security.Cryptography" namespace. The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption. These can be used for example in decrypting malicious payload for defense evasion.
windows
ScreenSaver Registry Key Set
mediumDetects registry key established after masqueraded .scr file execution using Rundll32 through desk.cpl
windows
Scripted Diagnostics Turn Off Check Enabled - Registry
mediumDetects enabling TurnOffCheck which can be used to bypass defense of MSDT Follina vulnerability
windows
Service Binary in User Controlled Folder
mediumDetects the setting of the "ImagePath" value of a service registry key to a path controlled by a non-administrator user such as "\AppData\" or "\ProgramData\". Attackers often use such directories for staging purposes. This rule might also trigger on badly written software, where if an attacker controls an auto starting service, they might achieve persistence or privilege escalation. Note that while ProgramData is a user controlled folder, software might apply strict ACLs which makes them only accessible to admin users. Remove such folders via filters if you experience a lot of noise.
windows
ServiceDll Hijack
mediumDetects changes to the "ServiceDLL" value related to a service in the registry. This is often used as a method of persistence.
windows
Session Manager Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
Suspicious Keyboard Layout Load
mediumDetects the keyboard preload installation with a suspicious keyboard layout, e.g. Chinese, Iranian or Vietnamese layout load in user session on systems maintained by US staff only
windows
Suspicious PowerShell In Registry Run Keys
mediumDetects potential PowerShell commands or code within registry run keys
windows
Suspicious Service Installed
mediumDetects installation of NalDrv or PROCEXP152 services via registry-keys to non-system32 folders. Both services are used in the tool Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU (https://github.com/hfiref0x/KDU)
windows
Suspicious Set Value of MSDT in Registry (CVE-2022-30190)
mediumDetects set value ms-msdt MSProtocol URI scheme in Registry that could be an attempt to exploit CVE-2022-30190.
windows
Suspicious Shell Open Command Registry Modification
mediumDetects modifications to shell open registry keys that point to suspicious locations typically used by malware for persistence. Generally, modifications to the `*\shell\open\command` registry key can indicate an attempt to change the default action for opening files, and various UAC bypass or persistence techniques involve modifying these keys to execute malicious scripts or binaries.
windows
System Scripts Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
UAC Disabled
mediumDetects when an attacker tries to disable User Account Control (UAC) by setting the registry value "EnableLUA" to 0.
windows
UAC Notification Disabled
mediumDetects when an attacker tries to disable User Account Control (UAC) notification by tampering with the "UACDisableNotify" value. UAC is a critical security feature in Windows that prevents unauthorized changes to the operating system. It prompts the user for permission or an administrator password before allowing actions that could affect the system's operation or change settings that affect other users. When "UACDisableNotify" is set to 1, UAC prompts are suppressed.
windows
UAC Secure Desktop Prompt Disabled
mediumDetects when an attacker tries to change User Account Control (UAC) elevation request destination via the "PromptOnSecureDesktop" value. The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts. When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.
windows
WFP Filter Added via Registry
mediumDetects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.
windows
Windows Defender Exclusions Added - Registry
mediumDetects the Setting of Windows Defender Exclusions
windows
Windows Recall Feature Enabled - Registry
mediumDetects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by setting the value of "DisableAIDataAnalysis" to "0". Adversaries may enable Windows Recall as part of post-exploitation discovery and collection activities. This rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.
windows
Winlogon AllowMultipleTSSessions Enable
mediumDetects when the 'AllowMultipleTSSessions' value is enabled. Which allows for multiple Remote Desktop connection sessions to be opened at once. This is often used by attacker as a way to connect to an RDP session without disconnecting the other users
windows
WinSock2 Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
Wow6432Node Classes Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
Wow6432Node CurrentVersion Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
Wow6432Node Windows NT CurrentVersion Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows
Command Executed Via Run Dialog Box - Registry
lowDetects execution of commands via the run dialog box on Windows by checking values of the "RunMRU" registry key. This technique was seen being abused by threat actors to deceive users into pasting and executing malicious commands, often disguised as CAPTCHA verification steps.
windows
ETW Logging Disabled For rpcrt4.dll
lowDetects changes to the "ExtErrorInformation" key in order to disable ETW logging for rpcrt4.dll
windows
ETW Logging Disabled For SCM
lowDetects changes to the "TracingDisabled" key in order to disable ETW logging for services.exe (SCM)
windows
MaxMpxCt Registry Value Changed
lowDetects changes to the "MaxMpxCt" registry value. MaxMpxCt specifies the maximum outstanding network requests for the server per client, which is used when negotiating a Server Message Block (SMB) connection with a client. Note if the value is set beyond 125 older Windows 9x clients will fail to negotiate. Ransomware threat actors and operators (specifically BlackCat) were seen increasing this value in order to handle a higher volume of traffic.
windows
Modification of IE Registry Settings
lowDetects modification of the registry settings used for Internet Explorer and other Windows components that use these settings. An attacker can abuse this registry key to add a domain to the trusted sites Zone or insert JavaScript for persistence
windows
New ODBC Driver Registered
lowDetects the registration of a new ODBC driver.
windows
Outlook Task/Note Reminder Received
lowDetects changes to the registry values related to outlook that indicates that a reminder was triggered for a Note or Task item. This could be a sign of exploitation of CVE-2023-23397. Further investigation is required to determine the success of an exploitation.
windows
Potential Raspberry Robin Registry Set Internet Settings ZoneMap
lowDetects registry modifications related to the proxy configuration of the system, potentially associated with the Raspberry Robin malware, as seen in campaigns running in Q1 2024. Raspberry Robin may alter proxy settings to circumvent security measures, ensuring unhindered connection with Command and Control servers for maintaining control over compromised systems if there are any proxy settings that are blocking connections.
windows
PowerShell Script Execution Policy Enabled
lowDetects the enabling of the PowerShell script execution policy. Once enabled, this policy allows scripts to be executed.
windows
PUA - Sysinternal Tool Execution - Registry
lowDetects the execution of a Sysinternals Tool via the creation of the "accepteula" registry key
windows
Shell Context Menu Command Tampering
lowDetects changes to shell context menu commands. Use this rule to hunt for potential anomalies and suspicious shell commands.
windows
Winget Admin Settings Modification
lowDetects changes to the AppInstaller (winget) admin settings. Such as enabling local manifest installations or disabling installer hash checks
windows
New Application in AppCompat
informationalA General detection for a new application in AppCompat. This indicates an application executing for the first time on an endpoint.
windows