Potential Uninstall Entry Concealment via HideUL or Registry Modification
Adversaries may hide malicious software such as remote-access tools from the Windows Programs and Features list by executing the HideUL utility or modifying the SystemComponent registry value.
Adversaries frequently employ techniques to conceal installed software from the Windows 'Programs and Features' control panel to maintain persistence and evade detection. This concealment is typically achieved through two primary methods: the execution of specialized utilities like 'Hide From Uninstall List' (HideUL) or direct manipulation of the Windows Registry. By setting the 'SystemComponent' value to '1' within the registry subkey of an application under 'Software\Microsoft\Windows\CurrentVersion\Uninstall', attackers can force the operating system to treat the application as a core system component, thereby removing it from the user-facing uninstallation list. This technique is commonly observed in the context of persistent remote-access tool deployment, security tool neutralization, and broader defense evasion strategies. Defenders must distinguish these unauthorized modifications from legitimate system administration, packaging, or kiosk hardening workflows that may also utilize the 'SystemComponent' flag.
Attack Chain
- Attacker gains initial access to a Windows system, often via phishing or exploited RMM tools.
- Attacker deploys a malicious payload (e.g., a remote-access trojan or persistent beacon).
- Attacker executes the payload on the target system.
- Attacker identifies the registry uninstall subkey for the installed malicious binary.
- Attacker executes 'HideUL.exe' or modifies the registry to set 'SystemComponent' to '1' for the target application entry.
- The application is hidden from the 'Programs and Features' UI to prevent user or administrator discovery.
- Attacker proceeds with the final objective, such as credential theft, lateral movement, or data exfiltration.
Impact
Successful concealment of malicious tools reduces the likelihood of detection by end-users and non-specialized administrators, increasing the dwell time of attackers within the environment. This technique is often associated with the deployment of ransomware and rogue remote-management software, which can lead to complete compromise of the affected host and potential lateral movement into the broader network.
Recommendation
Prioritize the identification of unauthorized 'SystemComponent' registry modifications.
- Deploy the provided Sigma rule to detect both the execution of HideUL binaries and suspicious modifications to registry uninstall keys.
- Establish a baseline of legitimate software management and deployment tools that utilize the 'SystemComponent' flag to reduce false positives.
- Review process parent-child relationships for registry modification events originating from non-administrative or unexpected binaries.
Immediate actions
Deploy the detection rule for HideUL and SystemComponent registry modifications.
Threat Hunt
Search for existing SystemComponent=1 entries in the registry that do not match authorized deployment software.
Detection coverage 1
Detect Potential Uninstall Entry Concealment
mediumDetects the execution of HideUL utilities or registry modifications setting SystemComponent to 1 to hide applications from the uninstall list.
Detection queries are available on the platform. Get full rules →