Skip to content
Threat Feed
medium advisory

SolarWinds Processes Modifying Registry to Disable Services

Adversaries may abuse compromised or legitimate SolarWinds binaries to disable security services by modifying Windows Registry 'Start' values, a technique used for defense evasion.

Adversaries targeting environments using SolarWinds software may leverage the high-level system permissions granted to these processes to perform defense evasion. By modifying specific Windows Registry keys that control service initialization, attackers can effectively disable security tools or critical system defenses. This behavior, often associated with supply chain compromises such as the Sunburst backdoor, involves SolarWinds binaries altering the 'Start' value of services to '4', which signifies that the service is disabled. Defenders should monitor for registry modifications originating from specific SolarWinds process names that correspond to standard system management tasks but result in the neutralization of security software. Given the broad deployment and deep system access typically required by SolarWinds, identifying unauthorized configuration changes at the registry level is a critical component of maintaining endpoint integrity.

Impact

Successful exploitation allows an adversary to neutralize security software and other critical services on a compromised host, facilitating undetected lateral movement and persistent presence. This technique has been historically associated with advanced persistent threat actors capable of executing complex supply chain compromises. Unauthorized service disabling can severely degrade the visibility of security teams, leading to potential data exfiltration or system-wide disruption within the target organization.

Recommendation

Detection engineering teams should implement monitoring for registry write events initiated by authorized SolarWinds processes where the target value is set to disabled.

  • Deploy the provided Sigma rule to monitor for registry modifications to service 'Start' keys.
  • Correlate registry modification events with process creation logs to verify the identity of the modifying process.
  • Establish a baseline for authorized configuration changes during scheduled maintenance windows to reduce false-positive alerts.
  • Review and restrict service-level permissions for SolarWinds processes to ensure they adhere to the principle of least privilege.

Immediate actions

Deploy the registry-based detection rule to identify service tampering

Detection Engineering 48h

Threat Hunt

Search for instances where SolarWinds binaries have modified registry keys ending in \Start

T1562.001 medium high confidence convert to detection

Data: Registry Event Logs (Sysmon 12/13)

Mitigations

Restrict registry write permissions for service configuration keys for service accounts running SolarWinds

short_term IT Operations

T1562.001

Detection coverage 1

Detect SolarWinds Process Disabling Services via Registry

medium

Detects when known SolarWinds binaries modify a service Start registry key to 4 (Disabled), which is a common defense evasion technique.

sigma tactics: defense_evasion techniques: T1562.001 sources: registry_set, windows

Detection queries are available on the platform. Get full rules →