Potential Persistence Via GlobalFlags

 Original Source: [Sigma source]
Title: Potential Persistence Via GlobalFlags
Status: test
Description:Detects registry persistence technique using the GlobalFlags and SilentProcessExit keys
References:
  -https://oddvar.moe/2018/04/10/persistence-using-globalflags-in-image-file-execution-options-hidden-from-autoruns-exe/
  -https://www.deepinstinct.com/2021/02/16/lsass-memory-dumps-are-stealthier-than-ever-before-part-2/
Author: Karneades, Jonhnathan Ribeiro, Florian Roth
Date: 2018-04-11
modified:2023-06-05
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.012'
  • -'car.2013-01-002'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection_global_flag:
    TargetObject|contains|all:
      -'\Microsoft\Windows NT\CurrentVersion\'
      -'\Image File Execution Options\'
      -'\GlobalFlag'

  selection_silent_process:
    TargetObject|contains|all:
      -'\Microsoft\Windows NT\CurrentVersion\'
      -'\SilentProcessExit\'

    TargetObject|contains:
      -'\ReportingMode'
      -'\MonitorProcess'

  condition:1 of selection_*
Falsepositives:
  -Unknown
Level: high