Tamper With Sophos AV Registry Keys

 Original Source: [Sigma source]
Title: Tamper With Sophos AV Registry Keys
Status: test
Description:Detects tamper attempts to sophos av functionality via registry key modification
References:
  -https://redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-02
modified:2023-08-17
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains:
      -'\Sophos Endpoint Defense\TamperProtection\Config\SAVEnabled'
      -'\Sophos Endpoint Defense\TamperProtection\Config\SEDEnabled'
      -'\Sophos\SAVService\TamperProtection\Enabled'

    Details: 'DWORD (0x00000000)'
  condition:selection
Falsepositives:
  -Some FP may occur when the feature is disabled by the AV itself, you should always investigate if the action was legitimate
Level: high