RunMRU Registry Key Deletion - Registry
Description
Detects attempts to delete the RunMRU registry key, which stores the history of commands executed via the run dialog. In the clickfix techniques, the phishing lures instruct users to open a run dialog through (Win + R) and execute malicious commands. Adversaries may delete this key to cover their tracks after executing commands.
Query · sigma
selection: TargetObject|endswith: \Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU condition: selection
Known false positives
- Unknown