Reg Add Suspicious Paths

 Original Source: [Sigma source]
Title: Reg Add Suspicious Paths
Status: test
Description:Detects when an adversary uses the reg.exe utility to add or modify new keys or subkeys
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1112/T1112.md
  -https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1562.001/T1562.001.md
  -https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-19
modified:2022-10-10
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_reg:
Image|endswith:'\reg.exe' OriginalFileName:'reg.exe'   selection_path:
    CommandLine|contains:
      -'\AppDataLow\Software\Microsoft\'
      -'\Policies\Microsoft\Windows\OOBE'
      -'\Policies\Microsoft\Windows NT\CurrentVersion\Winlogon'
      -'\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon'
      -'\CurrentControlSet\Control\SecurityProviders\WDigest'
      -'\Microsoft\Windows Defender\'

  condition:all of selection_*
Falsepositives:
  -Rare legitimate add to registry via cli (to these locations)
Level: high