Service Registry Key Deleted Via Reg.EXE

 Original Source: [Sigma source]
Title: Service Registry Key Deleted Via Reg.EXE
Status: test
Description:Detects execution of "reg.exe" commands with the "delete" flag on services registry key. Often used by attacker to remove AV software services
References:
  -https://www.virustotal.com/gui/file/2bcd5702a7565952c44075ac6fb946c7780526640d1264f692c7664c02c68465
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-01
modified:2023-02-04
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'reg.exe' OriginalFileName:'reg.exe'   selection_delete:
    CommandLine|contains: ' delete '
  selection_key:
    CommandLine|contains: '\SYSTEM\CurrentControlSet\services\'
  condition:all of selection_*
Falsepositives:
  -Unlikely
Level: high