Registry Modification of MS-settings Protocol Handler

 Original Source: [Sigma source]
Title: Registry Modification of MS-settings Protocol Handler
Status: test
Description:Detects registry modifications to the 'ms-settings' protocol handler, which is frequently targeted for UAC bypass or persistence. Attackers can modify this registry to execute malicious code with elevated privileges by hijacking the command execution path.
References:
  -https://thedfirreport.com/2021/12/13/diavol-ransomware/
  -https://www.trendmicro.com/en_us/research/25/f/water-curse.html
Author: frack113, Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2021-12-20
modified:2026-01-24
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1548.002'
  • -'attack.t1546.001'
  • -'attack.t1112'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_reg_img:
Image|endswith:'\reg.exe' OriginalFileName:'reg.exe'   selection_pwsh_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'powershell.exe'
      - 'pwsh.dll'
  selection_reg_cli:
    CommandLine|contains: 'add'
  selection_pwsh_cli:
    CommandLine|contains:
      -'New-ItemProperty'
      -'Set-ItemProperty'
      -'ni '
      -'sp '

  selection_cli_key:
    CommandLine|contains: '\ms-settings\shell\open\command'
  condition:(all of selection_reg_* or all of selection_pwsh_*) and selection_cli_key
Falsepositives:
  -Unknown
Level: medium