Cross-source coverage

T1112 / ATT&CK

Modify Registry

334 rules · 330 families across 8 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API.

The Registry may be modified in order to hide configuration information or malicious payloads via Obfuscated Files or Information. The Registry may also be modified to impair defenses, such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory.

The Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system. Often Valid Accounts are required, along with access to the remote system's SMB/Windows Admin Shares for RPC communication.

Finally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via Reg or other utilities using the Win32 API. Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.

Platforms
Windows
Telemetry
WinEventLog:Sysmon

How MITRE says to detect it DET0280

Behavior-Based Registry Modification Detection on Windows

Windows Analytic 0781

Behavior chain involving abnormal registry modifications via CLI, PowerShell, WMI, or direct API calls, especially targeting persistence, privilege escalation, or defense evasion keys, potentially followed by service restart or process execution. Such as editing Notify/Userinit/Startup keys, or disabling SafeDllSearchMode.

  • WinEventLog:Sysmon EventCode=13, 14
  • WinEventLog:Sysmon EventCode=1

SigmaHQ/sigma

96 rules
Detection Severity Format
FlowCloud Registry Markers Critical Sigma
OceanLotus Registry Activity Critical Sigma
OilRig APT Activity Critical Sigma
OilRig APT Registry Persistence Critical Sigma
OilRig APT Schedule Task Persistence - Security Critical Sigma
OilRig APT Schedule Task Persistence - System Critical Sigma
Registry Entries For Azorult Malware Critical Sigma
Blackbyte Ransomware Registry High Sigma
Blue Mockingbird High Sigma
Blue Mockingbird - Registry High Sigma

+ 86 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

79 rules
Detection Severity Format
Disable Registry Tool Undefined SPL
Disable Security Logs Using MiniNt Registry Undefined SPL
Disable Show Hidden Files Undefined SPL
Disable Windows App Hotkeys Undefined SPL
Disabling CMD Application Undefined SPL
Disabling ControlPanel Undefined SPL
Disabling NoRun Windows App Undefined SPL
Enable WDigest UseLogonCredential Registry Undefined SPL
FodHelper UAC Bypass Undefined SPL
Malicious InProcServer32 Modification Undefined SPL

+ 69 more from splunk/security_content → showing the 10 highest-severity

elastic/protections-artifacts

49 rules
Detection Severity Format
AllowProtectedRenames Registry Modification Undefined Elastic TOML
Attempt to Disable Driver via HVCIDisallowedImages Undefined Elastic TOML
Attempt to Disable Windows Driver Blocklist via Registry Undefined Elastic TOML
Attempt to Hide Files via Registry Modification Undefined Elastic TOML
Browser Native Messaging Registry Modification Undefined Elastic TOML
COM to .NET Redirection via Registry Undefined Elastic TOML
CrashDump Disabled via Registry Modification Undefined Elastic TOML
Defense Evasion via Registry Modification Undefined Elastic TOML
Disabling Hypervisor-protected Code Integrity via Registry Undefined Elastic TOML
Dual Persistence via Startup and Scheduled Task Undefined Elastic TOML

+ 39 more from elastic/protections-artifacts → showing the 10 highest-severity

elastic/detection-rules

40 rules
Detection Severity Format
Disabling Lsa Protection via Registry Modification High Elastic TOML
Modification of AmsiEnable Registry Key High Elastic TOML
Modification of WDigest Security Provider High Elastic TOML
Outlook Home Page Registry Modification High Elastic TOML
Persistence via Hidden Run Key Detected High Elastic TOML
Privilege Escalation via Windir Environment Variable High Elastic TOML
Suspicious ImagePath Service Creation High Elastic TOML
Suspicious Print Spooler Point and Print DLL High Elastic TOML
Suspicious Startup Shell Folder Modification High Elastic TOML
Code Signing Policy Modification Through Registry Medium Elastic TOML

+ 30 more from elastic/detection-rules → showing the 10 highest-severity

chronicle/detection-rules

30 rules
Detection Severity Format
blackbyte_ransomware_registry High YARA-L
potential_tampering_with_rdp_related_registry_keys_via_reg_exe High YARA-L
rdp_sensitive_settings_changed High YARA-L
restrictedadminmode_registry_value_tampering High YARA-L
shimcache_flush High YARA-L
wdigest_enable_uselogoncredential High YARA-L
disable_internal_tools_or_feature_in_registry Medium YARA-L
rdp_sensitive_settings_changed_to_zero Medium YARA-L
adwind_detection Undefined YARA-L
attempt_to_disable_windows_events_logging_via_registry Undefined YARA-L

+ 20 more from chronicle/detection-rules → showing the 10 highest-severity

socfortress/Wazuh-Rules

19 rules · 16 families
Detection Severity Format
Chafer Activity 2 variants Critical Wazuh XML
Chafer Activity 2 variants Critical Wazuh XML
Sysmon - Event 1: Process creation · Disable Security Notifications (T1112) High Wazuh XML
Sysmon - Event 1: Process creation · Disable Windows Task Manager via registry (T1112) High Wazuh XML
Sysmon - Event 1: Process creation · Load malware via App Paths registry (T1112) High Wazuh XML
Sysmon - Event 1: Process creation · Registry modification via regini.exe (T1112) High Wazuh XML
Sysmon - Event 1: Process creation · Registry modification via regsvr32 (T1112) High Wazuh XML
Sysmon - Event 1: Process creation · Registry modified via cmd.exe (T1112) High Wazuh XML
Sysmon - Event 1: Process creation · Registry modified via PowerShell Set-ItemProperty (T1112) High Wazuh XML
Sysmon - Event 1: Process creation · Registry modified via reg.exe (T1112) High Wazuh XML

+ 9 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

Wazuh Core Ruleset

17 rules
Detection Severity Format
Reg.exe modified registry using .reg file in suspicious location Critical Wazuh XML
added to the registry a subkey associated with UAC bypass by auto-elevated processes · win.eventdata.image = (?i)(cmd|powershell)\.exe High Wazuh XML
Command interpreter added to registry key associated to UAC bypass by auto-elevated processes High Wazuh XML
Possible addition of new item to Windows startup registry High Wazuh XML
Value added to registry key has Base64-like pattern High Wazuh XML
Modified registry key associated to UAC bypass by auto-elevated processes Medium Wazuh XML
Cannot read registry, registry keys missing. Low Wazuh XML
osquery: : Sticky registry key backdoor detected for key · osquery.name = StickyKeys_Registry_Backdoor Low Wazuh XML
Powershell executed "New-ItemProperty -Path". Possible addition of new item to registry Low Wazuh XML
Powershell script deleted an auto start entry registry key Low Wazuh XML

+ 7 more from Wazuh Core Ruleset → showing the 10 highest-severity

Azure/Azure-Sentinel

4 rules
Detection Severity Format
shimcache-flushed Undefined KQL
suspicious-base64-encoded-registry-keys Undefined KQL
suspicious-command-interpreters-added-to-registry Undefined KQL
suspicious-keywords-in-registry Undefined KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.