disable_internal_tools_or_feature_in_registry
Description
Detects registry modifications that change features of internal Windows tools (malware like Agent Tesla uses this technique)
Query · yara_l
events:
$reg.metadata.event_type = "REGISTRY_MODIFICATION"
(
(
(
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DisableCMD$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\StartMenuLogOff$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableChangePassword$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableLockWorkstation$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableRegistryTools$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskmgr$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\NoDispBackgroundPage$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\NoDispCPL$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Policies\\Microsoft\\Windows\\Explorer\\DisableNotificationCenter$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Policies\\Microsoft\\Windows\\System\\DisableCMD$`) nocase
) and
$reg.target.registry.registry_value_data = "DWORD (0x00000001)" nocase
)
or
(
(
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\ConsentPromptBehaviorAdmin$`) nocase or
re.regex($reg.target.registry.registry_key, `Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\InactivityTimeoutSecs$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\shutdownwithoutlogon$`) nocase or
re.regex($reg.target.registry.registry_key, `SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PushNotifications\\ToastEnabled$`) nocase or
re.regex($reg.target.registry.registry_key, `SYSTEM\\CurrentControlSet\\Control\\Storage\\Write Protection$`) nocase or
re.regex($reg.target.registry.registry_key, `SYSTEM\\CurrentControlSet\\Control\\StorageDevicePolicies\\WriteProtect$`) nocase
) and
$reg.target.registry.registry_value_data = "DWORD (0x00000000)" nocase
)
)
$reg.principal.hostname = $hostname
match:
$hostname over 5m
outcome:
//example usage of specifying test user and hostname to adjust risk score
$risk_score = max(if($reg.principal.user.userid = "user" and $reg.principal.hostname = "hostname", 0, 15))
$principal_hostname = array_distinct($reg.principal.hostname)
$principal_process_pid = array_distinct($reg.principal.process.pid)
$principal_process_file_full_path = array_distinct($reg.principal.process.file.full_path)
$principal_process_product_specific_process_id = array_distinct($reg.principal.process.product_specific_process_id)
$principal_user_userid = array_distinct($reg.principal.user.userid)
$target_registry_key = array_distinct($reg.target.registry.registry_key)
$target_registry_value_data = array_distinct($reg.target.registry.registry_value_data)
$log_type = array_distinct(strings.concat($reg.metadata.log_type,"/",$reg.metadata.product_event_type))
condition:
$reg