Sensitive Hive Access via Registry Backup
Description
Identifies access attempts to sensitive registry hives like the Security Account Manager (SAM) database file from the registry backdup folder. Adversaries may use this option to evade detections looking for registry hive direct access.
Query · eql
file where event.action == "open" and event.outcome == "success" and
file.path :
("?:\\Windows\\System32\\config\\RegBack\\SAM",
"?:\\Windows\\System32\\config\\RegBack\\SECURITY",
"?:\\Windows\\System32\\config\\RegBack\\SYSTEM") and
user.id != null and process.executable : "?:\\*" and process.pid != 4 and
not process.executable :
("?:\\Windows\\System32\\svchost.exe",
"?:\\Program Files (x86)\\*",
"?:\\Program Files\\*",
"?:\\Windows\\System32\\wuauclt.exe",
"?:\\$WINDOWS.~BT\\Sources\\SetupHost.exe",
"?:\\Windows\\System32\\vmwp.exe",
"?:\\Windows\\System32\\Dism.exe",
"?:\\Windows\\System32\\wbengine.exe",
"?:\\Windows\\System32\\mmc.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
"?:\\Windows\\System32\\sppsvc.exe",
"?:\\Windows\\System32\\backgroundTaskHost.exe",
"?:\\Windows\\System32\\lsass.exe",
"?:\\Windows\\System32\\taskhostw.exe",
"?:\\Windows\\System32\\taskhost.exe",
"?:\\Windows\\System32\\SearchProtocolHost.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*.exe",
"?:\\Program Files\\Windows Defender Advanced Threat Protection\\*.exe",
"?:\\Program Files\\Microsoft Monitoring Agent\\Agent\\*.exe",
"?:\\Windows\\System32\\SrTasks.exe",
"?:\\Windows\\System32\\rstrui.exe",
"?:\\Windows\\System32\\MRT.exe",
"?:\\Windows\\System32\\conhost.exe") and
not (process.code_signature.trusted == true and
process.code_signature.subject_name :
("ESET, spol. s r.o.", "Commvault Systems, Inc.", "Eric R. Zimmerman", "EFOLDER, INC.", "Absolute Software Corp.",
"Refraction Point, Inc"))