<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Orion Platform - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/orion-platform/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:41:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/orion-platform/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SolarWinds Processes Modifying Registry to Disable Services</title><link>https://feed.craftedsignal.io/briefs/2026-10-solarwinds-registry-tampering/</link><pubDate>Wed, 07 Oct 2026 16:41:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-solarwinds-registry-tampering/</guid><description>Adversaries may abuse compromised or legitimate SolarWinds binaries to disable security services by modifying Windows Registry 'Start' values, a technique used for defense evasion.</description><content:encoded><![CDATA[<p>Adversaries targeting environments using SolarWinds software may leverage the high-level system permissions granted to these processes to perform defense evasion. By modifying specific Windows Registry keys that control service initialization, attackers can effectively disable security tools or critical system defenses. This behavior, often associated with supply chain compromises such as the Sunburst backdoor, involves SolarWinds binaries altering the 'Start' value of services to '4', which signifies that the service is disabled. Defenders should monitor for registry modifications originating from specific SolarWinds process names that correspond to standard system management tasks but result in the neutralization of security software. Given the broad deployment and deep system access typically required by SolarWinds, identifying unauthorized configuration changes at the registry level is a critical component of maintaining endpoint integrity.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an adversary to neutralize security software and other critical services on a compromised host, facilitating undetected lateral movement and persistent presence. This technique has been historically associated with advanced persistent threat actors capable of executing complex supply chain compromises. Unauthorized service disabling can severely degrade the visibility of security teams, leading to potential data exfiltration or system-wide disruption within the target organization.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should implement monitoring for registry write events initiated by authorized SolarWinds processes where the target value is set to disabled.</p>
<ul>
<li>Deploy the provided Sigma rule to monitor for registry modifications to service 'Start' keys.</li>
<li>Correlate registry modification events with process creation logs to verify the identity of the modifying process.</li>
<li>Establish a baseline for authorized configuration changes during scheduled maintenance windows to reduce false-positive alerts.</li>
<li>Review and restrict service-level permissions for SolarWinds processes to ensure they adhere to the principle of least privilege.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>defense-evasion</category><category>supply-chain</category><category>windows</category><category>registry</category></item></channel></rss>