Suspicious Keyboard Layout Load

 Original Source: [Sigma source]
Title: Suspicious Keyboard Layout Load
Status: test
Description:Detects the keyboard preload installation with a suspicious keyboard layout, e.g. Chinese, Iranian or Vietnamese layout load in user session on systems maintained by US staff only
References:
  -https://renenyffenegger.ch/notes/Windows/registry/tree/HKEY_CURRENT_USER/Keyboard-Layout/Preload/index
  -https://github.com/SwiftOnSecurity/sysmon-config/pull/92/files
Author: Florian Roth (Nextron Systems)
Date: 2019-10-12
modified:2023-08-17
Tags:
  • -'attack.resource-development'
  • -'attack.t1588.002'
Logsource:
  • category: registry_set
  • product: windows
  • definition: Requirements: Sysmon config that monitors \Keyboard Layout\Preload subkey of the HKLU hives - see https://github.com/SwiftOnSecurity/sysmon-config/pull/92/files
Detection:
  selection_registry:
    TargetObject|contains:
      -'\Keyboard Layout\Preload\'
      -'\Keyboard Layout\Substitutes\'

    Details|contains:
      -'00000429'
      -'00050429'
      -'0000042a'

  condition:selection_registry
Falsepositives:
  -Administrators or users that actually use the selected keyboard layouts (heavily depends on the organisation's user base)
Level: medium