Potential KamiKakaBot Activity - Winlogon Shell Persistence
Description
Detects changes to the "Winlogon" registry key where a process will set the value of the "Shell" to a value that was observed being used by KamiKakaBot samples in order to achieve persistence.
Query · sigma
selection: TargetObject|endswith: \Microsoft\Windows NT\CurrentVersion\Winlogon\Shell Details|contains|all: - -nop -w h - $env - explorer.exe - Start-Process condition: selection
Known false positives
- Unlikely