Potential Ransomware Activity Using LegalNotice Message
Description
Detect changes to the "LegalNoticeCaption" or "LegalNoticeText" registry values where the message set contains keywords often used in ransomware ransom messages
Query · sigma
selection: TargetObject|contains: - \SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeCaption - \SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LegalNoticeText Details|contains: - encrypted - Unlock-Password - paying condition: selection
Known false positives
- Unknown