Removal Of AMSI Provider Registry Keys

 Original Source: [Sigma source]
Title: Removal Of AMSI Provider Registry Keys
Status: test
Description:Detects the deletion of AMSI provider registry key entries in HKLM\Software\Microsoft\AMSI. This technique could be used by an attacker in order to disable AMSI inspection.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
  -https://seclists.org/fulldisclosure/2020/Mar/45
Author: frack113
Date: 2021-06-07
modified:2025-10-07
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • category: registry_delete
Detection:
  selection:
    TargetObject|endswith:
      -'{2781761E-28E0-4109-99FE-B9D127C57AFE}'
      -'{A7C452EF-8E9F-42EB-9F2B-245613CA0DC9}'

  filter_main_defender:
    Image|startswith:
      -'C:\ProgramData\Microsoft\Windows Defender\Platform\'
      -'C:\Program Files\Windows Defender\'
      -'C:\Program Files (x86)\Windows Defender\'

    Image|endswith: '\MsMpEng.exe'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unlikely
Level: high