System Language Discovery via Reg.Exe

 Original Source: [Sigma source]
Title: System Language Discovery via Reg.Exe
Status: experimental
Description:Detects the usage of Reg.Exe to query system language settings. Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions, or avoid targeting certain locales to evade detection.
References:
  -https://scythe.io/threat-thursday/threatthursday-darkside-ransomware
Author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
Date: 2026-01-09
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.t1614.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\reg.exe' OriginalFileName:'reg.exe'   selection_cli:
    CommandLine|contains|all:
      -'query'
      -'Control\Nls\Language'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium