This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Reg Add Suspicious Paths
Original Source:
[Sigma source]
Title:
Reg Add Suspicious Paths
Status:
test
Description:
Detects when an adversary uses the reg.exe utility to add or modify new keys or subkeys
References:
-https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1112/T1112.md
-https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1562.001/T1562.001.md
-https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/
Author:
frack113, Nasreddine Bencherchali (Nextron Systems)
Date:
2022-08-19
modified:
2022-10-10
Tags:
-'attack.persistence'
-'attack.defense-impairment'
-'attack.t1112'
-'attack.t1685'
Logsource:
category: process_creation
product: windows
Detection:
selection_reg:
Image|endswith
:
'\reg.exe'
OriginalFileName
:
'reg.exe'
selection_path:
CommandLine|contains
:
-'\AppDataLow\Software\Microsoft\'
-'\Policies\Microsoft\Windows\OOBE'
-'\Policies\Microsoft\Windows NT\CurrentVersion\Winlogon'
-'\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon'
-'\CurrentControlSet\Control\SecurityProviders\WDigest'
-'\Microsoft\Windows Defender\'
condition
:
all of selection_*
Falsepositives:
-Rare legitimate add to registry via cli (to these locations)
Level:
high