MITRE ATT&CK technique
Modify Registry detection rulesT1112
Modify Registry (T1112) is a MITRE ATT&CK technique in the Defense Impairment tactic. This page lists the 96 community-maintained Sigma detection rules in the library mapped to T1112 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, rpc_firewall.
Top products
Tactic
FlowCloud Registry Markers
criticalDetects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
windows · registry_event
OceanLotus Registry Activity
criticalDetects registry keys created in OceanLotus (also known as APT32) attacks
windows · registry_event
OilRig APT Activity
criticalDetects OilRig activity as reported by Nyotron in their March 2018 report
windows · process_creation
OilRig APT Registry Persistence
criticalDetects OilRig registry persistence as reported by Nyotron in their March 2018 report
windows · registry_event
OilRig APT Schedule Task Persistence - Security
criticalDetects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
windows
OilRig APT Schedule Task Persistence - System
criticalDetects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
windows
Registry Entries For Azorult Malware
criticalDetects the presence of a registry key created during Azorult execution
windows · registry_event
Blackbyte Ransomware Registry
highDetects specific windows registry modifications made by BlackByte ransomware variants. BlackByte set three different registry values to escalate privileges and begin setting the stage for lateral movement and encryption. This rule triggers when any of the following registry keys are set to DWORD 1, however all three should be investigated as part of a larger BlackByte ransomware detection and response effort.
windows · registry_set
Blue Mockingbird
highAttempts to detect system changes made by Blue Mockingbird
windows · process_creation
Blue Mockingbird - Registry
highAttempts to detect system changes made by Blue Mockingbird
windows · registry_set
Change the Fax Dll
highDetect possible persistence using Fax DLL load when service restart
windows · registry_set
Change User Account Associated with the FAX Service
highDetect change of the user account associated with the FAX service to avoid the escalation problem.
windows · registry_set
CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry
highDetects changes to the "Ports" registry key with data that includes a Windows path or a file with a suspicious extension. This could be an attempt to exploit CVE-2020-1048 - a Windows Print Spooler elevation of privilege vulnerability.
windows · registry_set
DHCP Callout DLL Installation
highDetects the installation of a Callout DLL via CalloutDlls and CalloutEnabled parameter in Registry, which can be used to execute code in context of the DHCP server (restart required)
windows · registry_set
Disable Security Events Logging Adding Reg Key MiniNt
highDetects the addition of a key 'MiniNt' to the registry. Upon a reboot, Windows Event Log service will stop writing events.
windows · registry_event
Enable LM Hash Storage
highDetects changes to the "NoLMHash" registry value in order to allow Windows to store LM Hashes. By setting this registry value to "0" (DWORD), Windows will be allowed to store a LAN manager hash of your password in Active Directory and local SAM databases.
windows · registry_set
Enable LM Hash Storage - ProcCreation
highDetects changes to the "NoLMHash" registry value in order to allow Windows to store LM Hashes. By setting this registry value to "0" (DWORD), Windows will be allowed to store a LAN manager hash of your password in Active Directory and local SAM databases.
windows · process_creation
ETW Logging Disabled In .NET Processes - Registry
highPotential adversaries stopping ETW providers recording loaded .NET assemblies.
windows
ETW Logging Disabled In .NET Processes - Sysmon Registry
highPotential adversaries stopping ETW providers recording loaded .NET assemblies.
windows · registry_set
Imports Registry Key From an ADS
highDetects the import of a alternate datastream to the registry with regedit.exe.
windows · process_creation
Macro Enabled In A Potentially Suspicious Document
highDetects registry changes to Office trust records where the path is located in a potentially suspicious location
windows · registry_set
NET NGenAssemblyUsageLog Registry Key Tamper
highDetects changes to the NGenAssemblyUsageLog registry key. .NET Usage Log output location can be controlled by setting the NGenAssemblyUsageLog CLR configuration knob in the Registry or by configuring an environment variable (as described in the next section). By simplify specifying an arbitrary value (e.g. fake output location or junk data) for the expected value, a Usage Log file for the .NET execution context will not be created.
windows · registry_set
NetNTLM Downgrade Attack
highDetects NetNTLM downgrade attack
windows
NetNTLM Downgrade Attack - Registry
highDetects NetNTLM downgrade attack
windows · registry_event
New DNS ServerLevelPluginDll Installed
highDetects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
windows · registry_set
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
highDetects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
windows · process_creation
Non-privileged Usage of Reg or Powershell
highSearch for usage of reg or Powershell by non-privileged users to modify service configuration in registry
windows · process_creation
Office Macros Warning Disabled
highDetects registry changes to Microsoft Office "VBAWarning" to a value of "1" which enables the execution of all macros, whether signed or unsigned.
windows · registry_set
Outlook EnableUnsafeClientMailRules Setting Enabled - Registry
highDetects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros
windows · registry_set
Potential NetWire RAT Activity - Registry
highDetects registry keys related to NetWire RAT
windows · registry_add
Potential Persistence Via Outlook Home Page
highDetects potential persistence activity via outlook home page. An attacker can set a home page to achieve code execution and persistence by editing the WebView registry keys.
windows · registry_set
Potential Persistence Via Outlook Today Page
highDetects potential persistence activity via outlook today page. An attacker can set a custom page to execute arbitrary code and link to it via the registry values "URL" and "UserDefinedUrl".
windows · registry_set
Potential Qakbot Registry Activity
highDetects a registry key used by IceID in a campaign that distributes malicious OneNote files
windows · registry_event
Potential Tampering With RDP Related Registry Keys Via Reg.EXE
highDetects the execution of "reg.exe" for enabling/disabling the RDP service on the host by tampering with the 'CurrentControlSet\Control\Terminal Server' values
windows · process_creation
Potential Ursnif Malware Activity - Registry
highDetects registry keys related to Ursnif malware.
windows · registry_add
PowerShell Logging Disabled Via Registry Key Tampering
highDetects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging
windows · registry_set
RDP Sensitive Settings Changed
highDetects tampering of RDP Terminal Service/Server sensitive settings. Such as allowing unauthorized users access to a system via the 'fAllowUnsolicited' or enabling RDP via 'fDenyTSConnections', etc. Below is a list of registry keys/values that are monitored by this rule: - Shadow: Used to enable Remote Desktop shadowing, which allows an administrator to view or control a user's session. - DisableRemoteDesktopAntiAlias: Disables anti-aliasing for remote desktop sessions. - DisableSecuritySettings: Disables certain security settings for Remote Desktop connections. - fAllowUnsolicited: Allows unsolicited remote assistance offers. - fAllowUnsolicitedFullControl: Allows unsolicited remote assistance offers with full control. - InitialProgram: Specifies a program to run automatically when a user logs on to a remote computer. - ServiceDll: Used in RDP hijacking techniques to specify a custom DLL to be loaded by the Terminal Services service. - SecurityLayer: Specifies the security layer used for RDP connections.
windows · registry_set
RedMimicry Winnti Playbook Registry Manipulation
highDetects actions caused by the RedMimicry Winnti playbook
windows · registry_event
Reg Add Suspicious Paths
highDetects when an adversary uses the reg.exe utility to add or modify new keys or subkeys
windows · process_creation
Registry Modification for OCI DLL Redirection
highDetects registry modifications related to 'OracleOciLib' and 'OracleOciLibPath' under 'MSDTC' settings. Threat actors may modify these registry keys to redirect the loading of 'oci.dll' to a malicious DLL, facilitating phantom DLL hijacking via the MSDTC service.
windows · registry_set
Remote Registry Lateral Movement
highDetects remote RPC calls to modify the registry and possible execute code
rpc_firewall · application
RestrictedAdminMode Registry Value Tampering
highDetects changes to the "DisableRestrictedAdmin" registry value in order to disable or enable RestrictedAdmin mode. RestrictedAdmin mode prevents the transmission of reusable credentials to the remote system to which you connect using Remote Desktop. This prevents your credentials from being harvested during the initial connection process if the remote server has been compromise
windows · registry_set
RestrictedAdminMode Registry Value Tampering - ProcCreation
highDetects changes to the "DisableRestrictedAdmin" registry value in order to disable or enable RestrictedAdmin mode. RestrictedAdmin mode prevents the transmission of reusable credentials to the remote system to which you connect using Remote Desktop. This prevents your credentials from being harvested during the initial connection process if the remote server has been compromise
windows · process_creation
Security Event Logging Disabled via MiniNt Registry Key - Process
highDetects attempts to disable security event logging by adding the `MiniNt` registry key. This key is used to disable the Windows Event Log service, which collects and stores event logs from the operating system and applications. Adversaries may want to disable this service to prevent logging of security events that could be used to detect their activities.
windows · process_creation
Security Event Logging Disabled via MiniNt Registry Key - Registry Set
highDetects the addition of the 'MiniNt' key to the registry. Upon a reboot, Windows Event Log service will stop writing events. Windows Event Log is a service that collects and stores event logs from the operating system and applications. It is an important component of Windows security and auditing. Adversary may want to disable this service to disable logging of security events which could be used to detect their activities.
windows · registry_set
Service Binary in Suspicious Folder
highDetect the creation of a service with a service binary located in a suspicious directory
windows · registry_set
ShimCache Flush
highDetects actions that clear the local ShimCache and remove forensic evidence
windows · process_creation
Suspicious Registry Modification From ADS Via Regini.EXE
highDetects the import of an alternate data stream with regini.exe, regini.exe can be used to modify registry keys.
windows · process_creation
Sysmon Channel Reference Deletion
highPotential threat actor tampering with Sysmon manifest and eventually disabling it
windows
Terminal Server Client Connection History Cleared - Registry
highDetects the deletion of registry keys containing the MSTSC connection history
windows · registry_delete
Trust Access Disable For VBApplications
highDetects registry changes to Microsoft Office "AccessVBOM" to a value of "1" which disables trust access for VBA on the victim machine and lets attackers execute malicious macros without any Microsoft Office warnings.
windows · registry_set
Uncommon Microsoft Office Trusted Location Added
highDetects changes to registry keys related to "Trusted Location" of Microsoft Office where the path is set to something uncommon. Attackers might add additional trusted locations to avoid macro security restrictions.
windows · registry_set
User Shell Folders Registry Modification via CommandLine
highDetects modifications to User Shell Folders registry values via reg.exe or PowerShell, which could indicate persistence attempts. Attackers may modify User Shell Folders registry values to point to malicious executables or scripts that will be executed during startup. This technique is often used to maintain persistence on a compromised system by ensuring that malicious payloads are executed automatically.
windows · process_creation
Wdigest CredGuard Registry Modification
highDetects potential malicious modification of the property value of IsCredGuardEnabled from HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to disable Cred Guard on a system. This is usually used with UseLogonCredential to manipulate the caching credentials.
windows · registry_event
Wdigest Enable UseLogonCredential
highDetects potential malicious modification of the property value of UseLogonCredential from HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to enable clear-text credentials
windows · registry_set
Windows Event Log Access Tampering Via Registry
highDetects changes to the Windows EventLog channel permission values. It focuses on changes to the Security Descriptor Definition Language (SDDL) string, as modifications to these values can restrict access to specific users or groups, potentially aiding in defense evasion by controlling who can view or modify a event log channel. Upon execution, the user shouldn't be able to access the event log channel via the event viewer or via utilities such as "Get-EventLog" or "wevtutil".
windows · registry_set
Activate Suppression of Windows Security Center Notifications
mediumDetect set Notification_Suppress to 1 to disable the Windows security center notification
windows · registry_set
Add DisallowRun Execution to Registry
mediumDetect set DisallowRun to 1 to prevent user running specific computer program
windows · registry_set
Allow RDP Remote Assistance Feature
mediumDetect enable rdp feature to allow specific user to rdp connect on the targeted machine
windows · registry_set
ClickOnce Trust Prompt Tampering
mediumDetects changes to the ClickOnce trust prompt registry key in order to enable an installation from different locations such as the Internet.
windows · registry_set
CrashControl CrashDump Disabled
mediumDetects disabling the CrashDump per registry (as used by HermeticWiper)
windows · registry_set
Disable Internal Tools or Feature in Registry
mediumDetects registry modifications that change features of internal Windows tools (malware like Agent Tesla uses this technique)
windows · registry_set
Disable Windows Security Center Notifications
mediumDetect set UseActionCenterExperience to 0 to disable the Windows security center notification
windows · registry_set
DNS-over-HTTPS Enabled by Registry
mediumDetects when a user enables DNS-over-HTTPS. This can be used to hide internet activity or be used to hide the process of exfiltrating data. With this enabled organization will lose visibility into data such as query type, response and originating IP that are used to determine bad actors.
windows · registry_set
Imports Registry Key From a File
mediumDetects the import of the specified file to the registry with regedit.exe.
windows · process_creation
Microsoft Office Trusted Location Updated
mediumDetects changes to the registry keys related to "Trusted Location" of Microsoft Office. Attackers might add additional trusted locations to avoid macro security restrictions.
windows · registry_set
New BgInfo.EXE Custom DB Path Registry Configuration
mediumDetects setting of a new registry database value related to BgInfo configuration. Attackers can for example set this value to save the results of the commands executed by BgInfo in order to exfiltrate information.
windows · registry_set
New BgInfo.EXE Custom VBScript Registry Configuration
mediumDetects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom VBScript via "BgInfo.exe"
windows · registry_set
New BgInfo.EXE Custom WMI Query Registry Configuration
mediumDetects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom WMI query via "BgInfo.exe"
windows · registry_set
Potential Persistence Via Custom Protocol Handler
mediumDetects potential persistence activity via the registering of a new custom protocole handlers. While legitimate applications register protocole handlers often times during installation. And attacker can abuse this by setting a custom handler to be used as a persistence mechanism.
windows · registry_set
Potential Persistence Via Event Viewer Events.asp
mediumDetects potential registry persistence technique using the Event Viewer "Events.asp" technique
windows · registry_set
Potential Suspicious Registry File Imported Via Reg.EXE
mediumDetects the import of '.reg' files from suspicious paths using the 'reg.exe' utility
windows · process_creation
Potentially Suspicious Desktop Background Change Using Reg.EXE
mediumDetects the execution of "reg.exe" to alter registry keys that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
windows · process_creation
Potentially Suspicious Desktop Background Change Via Registry
mediumDetects registry value settings that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
windows · registry_set
Potentially Suspicious Image Load of Offreg.dll
mediumDetects potentially suspicious loading of the Offline Registry Library (offreg.dll). Offreg.dll enables direct read/write access to offline registry hives without invoking the Windows Registry API, bypassing its associated audit logging and telemetry. Attackers may abuse this to stealthily modify registry hives while evading detection mechanisms that rely on standard registry event logs.
windows · image_load
RDP Sensitive Settings Changed to Zero
mediumDetects tampering of RDP Terminal Service/Server sensitive settings. Such as allowing unauthorized users access to a system via the 'fAllowUnsolicited' or enabling RDP via 'fDenyTSConnections', etc.
windows · registry_set
Registry Explorer Policy Modification
mediumDetects registry modifications that disable internal tools or functions in explorer (malware like Agent Tesla uses this technique)
windows · registry_set
Registry Hide Function from User
mediumDetects registry modifications that hide internal tools or functions from the user (malware like Agent Tesla, Hermetic Wiper uses this technique)
windows · registry_set
Registry Manipulation via WMI Stdregprov
mediumDetects the usage of wmic.exe to modify Windows registry via the WMI StdRegProv class write methods (CreateKey, DeleteKey, SetStringValue, etc.). This behaviour could be potentially suspicious because it uses an alternative method to modify registry keys instead of legitimate registry tools like reg.exe or regedit.exe. Attackers specifically choose this technique to evade detection and bypass security monitoring focused on traditional registry modification commands.
windows · process_creation
Registry Modification Attempt Via VBScript
mediumDetects attempts to modify the registry using VBScript's CreateObject("Wscript.shell") and RegWrite methods via common LOLBINs. It could be an attempt to modify the registry for persistence without using straightforward methods like regedit.exe, reg.exe, or PowerShell. Threat Actors may use this technique to evade detection by security solutions that monitor for direct registry modifications through traditional tools.
windows · process_creation
Registry Modification Attempt Via VBScript - PowerShell
mediumDetects attempts to modify the registry using VBScript's CreateObject("Wscript.shell") and RegWrite methods embedded within PowerShell scripts or commands. Threat actors commonly embed VBScript code within PowerShell to perform registry modifications, attempting to evade detection that monitors for direct registry access through traditional tools. This technique can be used for persistence, defense evasion, and privilege escalation by modifying registry keys without using regedit.exe, reg.exe, or PowerShell's native registry cmdlets.
windows · ps_script
Registry Modification of MS-settings Protocol Handler
mediumDetects registry modifications to the 'ms-settings' protocol handler, which is frequently targeted for UAC bypass or persistence. Attackers can modify this registry to execute malicious code with elevated privileges by hijacking the command execution path.
windows · process_creation
Registry Tampering by Potentially Suspicious Processes
mediumDetects suspicious registry modifications made by suspicious processes such as script engine processes such as WScript, or CScript etc. These processes are rarely used for legitimate registry modifications, and their activity may indicate an attempt to modify the registry without using standard tools like regedit.exe or reg.exe, potentially for evasion and persistence.
windows · registry_event
Remote Registry Management Using Reg Utility
mediumRemote registry management using REG utility from non-admin workstation
windows
Removal of Potential COM Hijacking Registry Keys
mediumDetects any deletion of entries in ".*\shell\open\command" registry keys. These registry keys might have been used for COM hijacking activities by a threat actor or an attacker and the deletion could indicate steps to remove its tracks.
windows · registry_delete
Run Once Task Configuration in Registry
mediumRule to detect the configuration of Run Once registry key. Configured payload can be run by runonce.exe /AlternateShellStartup
windows · registry_event
Service Binary in User Controlled Folder
mediumDetects the setting of the "ImagePath" value of a service registry key to a path controlled by a non-administrator user such as "\AppData\" or "\ProgramData\". Attackers often use such directories for staging purposes. This rule might also trigger on badly written software, where if an attacker controls an auto starting service, they might achieve persistence or privilege escalation. Note that while ProgramData is a user controlled folder, software might apply strict ACLs which makes them only accessible to admin users. Remove such folders via filters if you experience a lot of noise.
windows · registry_set
Suspicious VBoxDrvInst.exe Parameters
mediumDetect VBoxDrvInst.exe run with parameters allowing processing INF file. This allows to create values in the registry and install drivers. For example one could use this technique to obtain persistence via modifying one of Run or RunOnce registry keys
windows · process_creation
Winlogon AllowMultipleTSSessions Enable
mediumDetects when the 'AllowMultipleTSSessions' value is enabled. Which allows for multiple Remote Desktop connection sessions to be opened at once. This is often used by attacker as a way to connect to an RDP session without disconnecting the other users
windows · registry_set
Access To .Reg/.Hive Files By Uncommon Applications
lowDetects file access requests to files ending with either the ".hive"/".reg" extension, usually associated with Windows Registry backups.
windows · file_access
ETW Logging Disabled For rpcrt4.dll
lowDetects changes to the "ExtErrorInformation" key in order to disable ETW logging for rpcrt4.dll
windows · registry_set
ETW Logging Disabled For SCM
lowDetects changes to the "TracingDisabled" key in order to disable ETW logging for services.exe (SCM)
windows · registry_set
Modification of IE Registry Settings
lowDetects modification of the registry settings used for Internet Explorer and other Windows components that use these settings. An attacker can abuse this registry key to add a domain to the trusted sites Zone or insert JavaScript for persistence
windows · registry_set
Potential Raspberry Robin Registry Set Internet Settings ZoneMap
lowDetects registry modifications related to the proxy configuration of the system, potentially associated with the Raspberry Robin malware, as seen in campaigns running in Q1 2024. Raspberry Robin may alter proxy settings to circumvent security measures, ensuring unhindered connection with Command and Control servers for maintaining control over compromised systems if there are any proxy settings that are blocking connections.
windows · registry_set
Registry Modification Via Regini.EXE
lowDetects the execution of regini.exe which can be used to modify registry keys, the changes are imported from one or more text files.
windows · process_creation
Run Once Task Execution as Configured in Registry
lowThis rule detects the execution of Run Once task as configured in the registry
windows · process_creation