This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
Original Source:
[Sigma source]
Title:
Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
Status:
test
Description:
Detects the usage of "reg.exe" to tamper with different Windows Defender registry keys in order to disable some important features related to protection and detection
References:
-https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/
-https://github.com/swagkarna/Defeat-Defender-V1.2.0/tree/ae4059c4276da6f6303b8f53cdff085ecae88a91
-https://www.elevenforum.com/t/video-guide-how-to-completely-disable-microsoft-defender-antivirus.14608/page-2
-https://tria.ge/241231-j9yatstqbm/behavioral1
Author:
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems)
Date:
2022-03-22
modified:
2025-06-04
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
category: process_creation
product: windows
Detection:
selection_root_img:
Image|endswith
:
'\reg.exe'
OriginalFileName
:
'reg.exe'
selection_root_path:
CommandLine|contains
:
-'SOFTWARE\Microsoft\Windows Defender\'
-'SOFTWARE\Policies\Microsoft\Windows Defender Security Center'
-'SOFTWARE\Policies\Microsoft\Windows Defender\'
selection_dword_0:
CommandLine|contains|all
:
-' add '
-'d 0'
CommandLine|contains
:
-'DisallowExploitProtectionOverride'
-'EnableControlledFolderAccess'
-'MpEnablePus'
-'PUAProtection'
-'SpynetReporting'
-'SubmitSamplesConsent'
-'TamperProtection'
selection_dword_1:
CommandLine|contains|all
:
-' add '
-'d 1'
CommandLine|contains
:
-'DisableAccess'
-'DisableAntiSpyware'
-'DisableAntiSpywareRealtimeProtection'
-'DisableAntiVirus'
-'DisableAntiVirusSignatures'
-'DisableArchiveScanning'
-'DisableBehaviorMonitoring'
-'DisableBlockAtFirstSeen'
-'DisableCloudProtection'
-'DisableConfig'
-'DisableEnhancedNotifications'
-'DisableIntrusionPreventionSystem'
-'DisableIOAVProtection'
-'DisableNetworkProtection'
-'DisableOnAccessProtection'
-'DisablePrivacyMode'
-'DisableRealtimeMonitoring'
-'DisableRoutinelyTakingAction'
-'DisableScanOnRealtimeEnable'
-'DisableScriptScanning'
-'DisableSecurityCenter'
-'Notification_Suppress'
-'SignatureDisableUpdateOnStartupWithoutEngine'
condition
:
all of selection_root_* and 1 of selection_dword_*
Falsepositives:
-Rare legitimate use by administrators to test software (should always be investigated)
Level:
high