Potential Attachment Manager Settings Associations Tamper
Description
Detects tampering with attachment manager settings policies associations to lower the default file type risks (See reference for more information)
Query · sigma
selection_main: TargetObject|contains: \SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Associations\ selection_value_default_file_type_rsik: TargetObject|endswith: \DefaultFileTypeRisk Details: DWORD (0x00006152) selection_value_low_risk_filetypes: TargetObject|endswith: \LowRiskFileTypes Details|contains: - .zip; - .rar; - .exe; - .bat; - .com; - .cmd; - .reg; - .msi; - .htm; - .html; condition: selection_main and 1 of selection_value_*
Known false positives
- Unlikely