CrashDump Disabled via Registry Modification


Description

Identifies attempt to disable memory crashdump via registry modification. Malware using kernel mode component may perform this action to limit exposure in the case of an unexpected system crash.

Query · eql

registry where registry.value : "CrashDumpEnabled" and registry.data.strings : "0" and
 process.executable != null and
 not (user.id in ("S-1-5-18", "S-1-5-19", "S-1-5-20") and 
      process.executable : ("?:\\Windows\\System32\\svchost.exe", "?:\\Windows\\System32\\msiexec.exe")) and
 not process.executable : (
       "?:\\Windows\\System32\\SystemPropertiesAdvanced.exe",
       /* TBR */
       "?:\\Program Files (x86)\\Citrix\\Workspace Environment Management Agent\\Citrix.Wem.Agent.Service.exe")
Raw source CrashDump Disabled via Registry Modification · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
Identifies attempt to disable memory crashdump via registry modification. Malware using kernel mode component may
perform this action to limit exposure in the case of an unexpected system crash.
"""
id = "77ca3fcc-f607-45e0-837e-e4173e4ffc2a"
license = "Elastic License v2"
name = "CrashDump Disabled via Registry Modification"
os_list = ["windows"]
reference = [
    "https://www.elastic.co/security-labs/elastic-protects-against-data-wiper-malware-targeting-ukraine-hermeticwiper",
    "https://docs.microsoft.com/en-us/troubleshoot/windows-server/performance/memory-dump-file-options",
]
version = "1.0.31"

query = '''
registry where registry.value : "CrashDumpEnabled" and registry.data.strings : "0" and
 process.executable != null and
 not (user.id in ("S-1-5-18", "S-1-5-19", "S-1-5-20") and 
      process.executable : ("?:\\Windows\\System32\\svchost.exe", "?:\\Windows\\System32\\msiexec.exe")) and
 not process.executable : (
       "?:\\Windows\\System32\\SystemPropertiesAdvanced.exe",
       /* TBR */
       "?:\\Program Files (x86)\\Citrix\\Workspace Environment Management Agent\\Citrix.Wem.Agent.Service.exe")
'''

min_endpoint_version = "7.15.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1112"
name = "Modify Registry"
reference = "https://attack.mitre.org/techniques/T1112/"


[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"

[internal]
min_endpoint_version = "7.15.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.