Shell Open Registry Keys Manipulation

 Original Source: [Sigma source]
Title: Shell Open Registry Keys Manipulation
Status: test
Description:Detects manipulation of shell open command registry keys such as "ms-settings" and "exefile", which are commonly abused to achieve UAC bypass (e.g. via fodhelper.exe) or establish persistence through file association hijacking.
References:
  -https://github.com/hfiref0x/UACME
  -https://winscripting.blog/2017/05/12/first-entry-welcome-and-uac-bypass/
  -https://github.com/RhinoSecurityLabs/Aggressor-Scripts/tree/master/UACBypass
  -https://tria.ge/211119-gs7rtshcfr/behavioral2 [Lokibot sample from Nov 2021]
Author: Christian Burkard (Nextron Systems)
Date: 2021-08-30
modified:2026-08-27
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1548.002'
  • -'attack.t1546.001'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection_1:
    EventType: 'SetValue'
    TargetObject|endswith: 'Classes\ms-settings\shell\open\command\SymbolicLinkValue'
    Details|contains: '\Software\Classes\{'
  selection_2:
    TargetObject|endswith: 'Classes\ms-settings\shell\open\command\DelegateExecute'
  selection_3:
    EventType: 'SetValue'
    TargetObject|endswith:
      -'Classes\ms-settings\shell\open\command\(Default)'
      -'Classes\exefile\shell\open\command\(Default)'

  filter_main_empty:
    Details: '(Empty)'
  filter_main_default_com:
    Details:
      -'{4813071a-41ad-44a2-9835-886d2f63ca30}'
      -'{A56A841F-E974-45C1-8001-7E3F8A085917}'
      -'{4ED3A719-CEA8-4BD9-910D-E252F997AFC2}'
      -'{BFEC0C93-0B7D-4F2C-B09C-AFFFC4BDAE78}'

  condition:1 of selection_* and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high