Skip to content
Threat Feed

Tag

Registry

75 briefs RSS
high advisory

Detection of Potential Persistence via Logon Script Registry Modification

Detection of adversaries modifying the UserInitMprLogonScript registry value to establish persistence via logon scripts.

persistence windows registry defense-evasion
1r 1t
high advisory

Windows Persistence via GlobalFlags and SilentProcessExit Registry Keys

Adversaries abuse the Image File Execution Options (IFEO) registry keys to establish persistence or intercept process termination by configuring GlobalFlags and SilentProcessExit mechanisms.

persistence privilege-escalation registry windows
1r 1t
medium advisory

Modification of CurrentControlSet Registry Autorun Extensibility Points

Detects unauthorized modification of Windows Registry keys within CurrentControlSet used for persistent execution via system extensibility points.

persistence privilege-escalation registry
1r 2t
high advisory

Tampering of RDP Terminal Services Registry Settings

Adversaries, including the DarkGate malware operators, modify sensitive registry keys associated with Terminal Services to facilitate session hijacking, unauthorized remote access, and defense impairment.

rdp registry persistence defense-impairment
1r 2t
medium advisory

Modification of Outlook Security Registry Settings

Detects unauthorized modifications to Microsoft Outlook security-related registry keys that may be used to weaken email protections or establish persistence.

persistence windows registry outlook
1t
high advisory

Abuse of Windows Time Service for Persistence via TimeProvider Registry

Adversaries may achieve persistence by registering a malicious DLL within the Windows Time service (W32Time) configuration, allowing for arbitrary code execution upon system boot.

persistence windows registry
1r 1t
high advisory

Tampering with Windows Defender via Registry Modifications

Adversaries frequently disable Windows Defender security features by modifying specific registry keys to impair endpoint detection and response capabilities.

defense-impairment windows-defender registry
1r
high advisory

Potential System Persistence via AutodialDLL Registry Modification

Adversaries can achieve persistence by modifying the AutodialDLL registry key to load a malicious DLL through the Windows Winsock2 library.

persistence windows registry
1r 1t
medium advisory

Modification of Registry Autorun Keys in Wow6432Node

Detection of registry modifications targeting Autostart Extensibility Points within the Wow6432Node hive, a common technique for achieving persistence on Windows systems.

persistence privilege-escalation registry windows
1r
medium advisory

Modification of Windows NT CurrentVersion Autorun Registry Keys

Detection of unauthorized modifications to Windows registry keys that enable persistence through autostart extensibility points within the NT CurrentVersion hive.

persistence privilege-escalation registry
1r 1t
high advisory

Abuse of Winlogon Notify Registry Keys for Persistence

Adversaries can achieve persistence and privilege escalation by modifying the Winlogon Notify registry key to trigger the execution of arbitrary DLLs during user login.

persistence privilege-escalation registry
1r 2t
medium advisory

Detection of UAC Notification Suppression via Registry

Detection of attackers suppressing Windows User Account Control (UAC) prompts by modifying the UACDisableNotify registry value to facilitate unauthorized system changes.

privilege-escalation windows registry
1r 1t
medium advisory

Windows Registry Explorer Policy Modifications

Adversaries, including the Agent Tesla malware, modify Windows Registry keys under Explorer Policies to impair user access to system tools and desktop functionality.

defense-impairment persistence windows registry
1r 1t
medium advisory

Windows Application Shim Database Persistence

Adversaries can achieve persistence and privilege escalation by installing malicious shim databases to intercept and redirect application execution.

persistence privilege-escalation registry windows
1r 2t
medium advisory

COM Hijacking via Scrobj.dll Persistence

Adversaries may achieve persistence or privilege escalation by hijacking COM object registrations associated with scrobj.dll to execute arbitrary scriptlet code.

persistence privilege-escalation windows registry
1r 1t
high advisory

Outlook WebView Registry Modification for Persistence

Adversaries can achieve persistence and code execution by modifying the Outlook WebView registry keys to point to a malicious URL.

Outlook persistence registry windows
1r 1t
medium advisory

Potential Persistence via Event Viewer Registry Redirection

An adversary can achieve persistence or defense impairment by modifying Windows registry keys to redirect Event Viewer's 'Events.asp' link handling to a malicious binary or command line.

persistence defense-impairment windows registry
1r 1t
high advisory

Detection of Microsoft Office Protected View Disablement

Adversaries modify registry keys to disable Microsoft Office Protected View security controls, facilitating the execution of malicious documents.

Microsoft Office defense-impairment registry-tampering microsoft-office persistence privilege-escalation registry windows office
2r 1t updated
medium advisory

Detection of Unauthorized Root or CA Certificate Installation

Adversaries can install malicious root or CA certificates into the Windows registry to facilitate traffic interception, bypass security controls, and establish persistence.

windows registry certificate-management
1r 1t
medium advisory

Registry Modifications Used to Obfuscate System UI Elements

Malicious actors, including those behind Agent Tesla and Hermetic Wiper, utilize specific registry modifications to hide system interface elements from users as a defensive impairment technique.

persistence defense-impairment windows registry
1r 1t
medium advisory

Detection of Registry Modifications to Disable Hidden File Visibility

Adversaries frequently modify Windows registry keys to prevent users from viewing hidden and system files, a technique used to maintain persistence and camouflage malicious artifacts.

stealth registry persistence
1r 1t
medium advisory

Registry Modification to Conceal File Extensions

Adversaries modify Windows registry keys to hide file extensions and system files, facilitating the masquerading of malicious executables.

persistence windows registry
1r 1t
medium advisory

Modification of DisallowRun Registry Policy

An adversary or administrator can modify the DisallowRun registry key to prevent specific applications from executing, a technique often used to impair security tools or enforce restrictive environment configurations.

persistence defense-impairment registry windows
1r 1t
medium advisory

Defense Impairment via Windows Firewall Registry Modification

Adversaries disable the Windows Firewall by modifying specific registry keys to bypass network security controls and facilitate lateral movement or data exfiltration.

defense-impairment windows registry firewall
1r 1t
high advisory

Windows Event Log Access Tampering Via Registry

Attackers may modify registry-based Security Descriptor Definition Language (SDDL) strings for Windows Event Log channels to impair defensive monitoring by restricting access to log data.

defense-evasion persistence windows registry
1r 2t
medium advisory

Modification of Session Manager Autorun Registry Keys

This brief documents detection logic for monitoring unauthorized modifications to Windows Session Manager registry keys, which are often leveraged by attackers for persistence and privilege escalation.

persistence privilege-escalation registry windows
1r 2t
medium advisory

Modification of Autostart Extensibility Point Registry Keys

Adversaries frequently modify Windows Autostart Extensibility Point (ASEP) registry keys to establish persistence, requiring robust monitoring of registry set events.

persistence privilege-escalation registry windows
1r 1t
medium advisory

ServiceDLL Registry Hijack for Persistence

Adversaries manipulate the ServiceDLL registry value within Windows service configurations to achieve persistence by forcing the loading of unauthorized malicious dynamic link libraries.

persistence windows registry
1r 1t
high advisory

Abuse of Shell Open Registry Keys for Persistence and UAC Bypass

Adversaries manipulate Windows shell open command registry keys to facilitate User Account Control (UAC) bypass and establish persistence through file association hijacking.

persistence privilege-escalation registry
1r 2t
high advisory

Suspicious Modification of Windows Legal Notice Registry Keys

Adversaries modify Windows LegalNotice registry values to display custom ransom messages during the login process as part of an extortion campaign.

ransomware registry windows impact
1r 1t
medium advisory

Detection of Windows Registry Modifications to Disable System Features

Adversaries, including operators of Agent Tesla and Batloader, modify Windows Registry keys to disable system administration tools and security features, hindering incident response and persistence.

Windows defense-impairment persistence registry
1r 2t
medium advisory

Abuse of PYTHONPATH for Python Module Hijacking and Persistence

Adversaries are modifying the PYTHONPATH environment variable during Python package installation to redirect module imports, enabling code execution and persistence whenever Python is invoked.

python persistence registry supply-chain windows
1r 2t
high advisory

Detection of Registry Keys Used for Persistence

This brief outlines a detection strategy for identifying modifications to Windows registry keys commonly used for persistence, including Run, Winlogon, and Image File Execution Options, enabling detection engineers to alert on unauthorized system startup entries for malicious code execution to prevent persistent access.

Splunk Enterprise +3 persistence registry windows endpoint malware
1r 1t
high advisory

Detection of Renamed Sysinternals Tool Usage via Registry EULA Key

This brief details a detection strategy for identifying the use of renamed Sysinternals utilities by monitoring for suspicious modifications to the 'EulaAccepted' registry key, indicating potential post-exploitation activity or defense evasion on Windows systems.

defense-evasion post-exploitation sysinternals registry windows
1r 1t
high advisory

Suspicious Execution of Renamed Sysinternals Tools via Registry

This brief details a detection method for adversaries using renamed Sysinternals tools, a legitimate suite of utilities, to evade endpoint detection by triggering the `EulaAccepted` registry key creation, potentially leading to unauthorized system manipulation or data access on Windows systems.

sysinternals evasion registry windows pua
1r 2t
medium advisory

Windows Registry Modification Risk Behavior Detection

This analytic identifies instances where three or more distinct registry modification events associated with MITRE ATT&CK Technique T1112 are detected, leveraging Splunk's Risk data model to detect persistence, hiding malicious configurations, or erasing forensic evidence.

Splunk Enterprise +2 registry persistence defense-evasion windows
2r 2t
high threat

Persistence via WMI Standard Registry Provider

The rule identifies the use of Windows Management Instrumentation StdRegProv (registry provider) to modify commonly abused registry locations for persistence by detecting registry changes made by WmiPrvSe.exe in specific registry paths.

Windows Management Instrumentation persistence registry wmi windows
3r 1t
high advisory

Persistence via Hidden Run Key Detected

This rule detects a persistence mechanism that utilizes the NtSetValueKey native API to create a hidden (null terminated) registry key, evading detection from system utilities.

Elastic Defend +4 persistence registry windows
2r 1t
high threat

Suspicious ImagePath Service Creation in Registry

Detection of suspicious ImagePath values written to the registry, indicating potential persistence or privilege escalation via abnormal service creation involving command interpreters or named pipes.

Elastic Endgame +4 persistence registry service_creation
2r 1t
high advisory

Suspicious Startup Shell Folder Modification

Detects suspicious modifications to the Windows Startup shell folder, a technique used to bypass detections monitoring file creation in the Windows Startup folder.

Microsoft Defender XDR +4 persistence registry startup
2r 1t
high advisory

RegPwnBOF Registry Symlink Race Condition Exploit

RegPwnBOF exploits a registry symlink race condition in the Windows Accessibility ATConfig mechanism, enabling a normal user to write arbitrary values to protected HKLM registry keys for persistence and privilege escalation.

registry symlink race-condition accessibility privilege-escalation persistence windows
2r 2t
high advisory

Outlook Home Page Registry Modification for Command and Control or Persistence

Attackers abuse the Outlook Home Page functionality by modifying specific registry keys to point to attacker-controlled URLs or file paths, enabling command and control or persistence on compromised Windows systems.

Outlook registry command-and-control persistence windows
2r 2t
medium advisory

Windows SIP Provider Modification for Defense Evasion

This brief covers the modification of Subject Interface Package (SIP) providers on Windows systems, a technique used by attackers to bypass signature validation checks and inject malicious code into critical processes, ultimately leading to defense evasion.

Windows defense-evasion registry
1r 1t
low advisory

Netsh Helper DLL Persistence

Attackers may abuse the Netsh Helper DLL functionality by adding malicious DLLs to execute payloads every time the netsh utility is executed via administrators or scheduled tasks, achieving persistence.

Microsoft Defender XDR +3 persistence windows netsh registry
2r 2t
low advisory

Netsh Helper DLL Persistence via Registry Modification

Attackers may establish persistence by adding a malicious DLL as a Netsh Helper, which executes whenever the Netsh utility is run, often abusing this mechanism to execute malicious payloads.

Windows persistence registry netsh
2r 3t
high advisory

AMSI Enable Registry Key Modification for Defense Evasion

Adversaries modify the AmsiEnable registry key to 0 to disable Windows Script AMSI scanning, bypassing AMSI protections for Windows Script Host or JScript execution.

Microsoft Defender XDR +4 defense-evasion amsi registry windows
2r 1t
high advisory

Potential Disabling of Windows Defender Antivirus via Registry Modification

An attacker might attempt to disable Windows Defender Antivirus by modifying specific registry keys, potentially leading to a system vulnerable to malware and other threats.

Windows Defender Antivirus windowsdefender registry antivirus disable malware
2r 1t
medium advisory

Potential NetNTLMv1 Downgrade Attack via Registry Modification

Attackers modify the Windows registry to weaken NTLM authentication, forcing a downgrade to the less secure NTLMv1 protocol, potentially leading to credential compromise.

Windows ntlm downgrade registry defense-evasion credential-access
2r 2t
medium advisory

Werfault ReflectDebugger Persistence Abuse

Attackers can achieve persistence by modifying the ReflectDebugger registry key associated with Windows Error Reporting (Werfault) to execute arbitrary code when Werfault is invoked with the `-pr` parameter.

Windows persistence registry
2r 2t
high advisory

Windows Defender Real-Time Behavior Monitoring Disabled via Registry Modification

Attackers modify Windows Registry keys to disable Windows Defender real-time behavior monitoring, a tactic used by malware to evade detection and persist on compromised systems.

Windows Defender windows defense-evasion registry endpoint
2r 1t
low advisory

Wallpaper Modification Detection

Detection of unauthorized or suspicious wallpaper modifications on endpoints can indicate malicious activity or policy violations.

Windows endpoint wallpaper modification registry policy violation
3r 1t
medium advisory

Unusual Persistence via Services Registry Modification

Adversaries may modify the Windows services registry keys directly to stealthily persist through abnormal service creation or modification of an existing service, bypassing standard APIs, detected by monitoring registry changes related to service DLLs and image paths.

Windows persistence registry services
2r 3t
high advisory

LSASS Protection Policy Disabled via Registry Modification

Attackers may disable Protected Process Light (PPL) protection for the LSASS process by modifying specific registry keys, allowing for credential dumping and other malicious activities.

Windows credential-access defense-evasion lsass ppl registry
2r 2t
medium advisory

PowerShell Script Block Logging Disabled via Registry Modification

Attackers may disable PowerShell Script Block Logging by modifying the registry to conceal their activities on the host and evade detection by setting the `EnableScriptBlockLogging` registry value to 0, impacting security monitoring and incident response capabilities.

Defender XDR +2 defense-evasion powershell registry
2r 2t
high advisory

ETW Registry Disabled via Registry Modification

Attackers may disable Event Tracing for Windows (ETW) for the .NET Framework by modifying the ETWEnabled registry value, allowing them to evade endpoint detection and response (EDR) tools and hide malicious activity.

.NETFramework +3 etw registry defense-evasion windows t1127 t1685
2r 1t
medium advisory

Windows Software Discovery via PowerShell Registry Queries

Attackers use PowerShell to query the Windows registry's Uninstall key to discover installed software and identify potential vulnerabilities for exploitation.

Splunk Enterprise +2 software-discovery powershell registry reconnaissance
2r 3t
high advisory

Windows EventLog Security Descriptor Tampering

This analytic detects suspicious modifications to the EventLog security descriptor registry value, specifically the 'CustomSD' value, within the registry path 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\<Channel>\CustomSD', which can be used for defense evasion by attackers.

Sysmon +3 defense-evasion eventlog registry tampering
2r 1t
medium advisory

Windows Defender Throttle Rate Modification

An attacker modifies the Windows Defender ThrottleDetectionEventsRate registry setting to reduce the frequency of logged detection events, potentially evading detection.

Splunk Enterprise +2 windows defender registry defense-evasion
2r 1t
high advisory

Windows Defender Threat Action Modification via Registry

An attacker modifies the Windows Defender ThreatSeverityDefaultAction registry setting to weaken defenses, potentially leading to unaddressed threats and system compromise.

Windows Defender +3 windows endpoint registry defense-evasion
2r
medium advisory

Windows Defender Reporting Disabled via Registry Modification

Attackers modify the Windows registry to disable Windows Defender generic reports, preventing error reports and potentially hiding malicious activity.

Windows Defender defense-evasion windows registry
2r 1t
high advisory

Windows Defender Exclusion Registry Modification

Adversaries modify Windows Defender exclusion registry entries to bypass antivirus and execute malicious code undetected, potentially leading to persistence and further malicious activities.

Windows Defender +3 windows endpoint registry defender exclusion defense-evasion malware
2r 1t
medium advisory

Uncommon Registry Persistence Change Detection

This rule detects changes to uncommon registry persistence keys on Windows systems that are not commonly used or modified by legitimate programs, which could indicate an adversary's attempt to persist in a stealthy manner by modifying registry keys for persistence, ensuring malicious code executes on startup or during specific events.

Windows persistence registry
2r 2t
medium advisory

Suspicious Access to Windows Product Key Registry

Detection of processes attempting to access the Windows registry to recover product keys, potentially indicating malware activity, unauthorized security bypass, or data exfiltration.

Windows registry product-key malware
2r 1t
low advisory

Startup or Run Key Registry Modification

Attackers modify registry run keys or startup keys to achieve persistence by referencing a program that executes when a user logs in or the system boots.

Elastic Defend +6 persistence registry runkey
3r 2t
medium advisory

Registry Persistence via AppInit DLL Modification

Modification of the AppInit DLLs registry keys on Windows systems allows attackers to execute code in every process that loads user32.dll, establishing persistence and potentially escalating privileges.

Microsoft Windows +6 persistence defense-evasion appinit-dlls registry windows
2r 2t
medium advisory

Microsoft Defender 'Block at First Seen' Feature Disabled

An attacker disables the Microsoft Defender 'Block at First Seen' feature to allow potentially malicious files to execute without initial scrutiny, increasing the risk of malware infection and data compromise.

Microsoft Defender defender malware block-at-first-seen registry powershell
2r 1t
medium advisory

Encoded Executable Stored in the Registry

This rule detects registry write modifications hiding encoded portable executables, indicative of adversary defense evasion by avoiding storing malicious content directly on disk.

Elastic Defend +3 defense-evasion registry windows
2r 3t 1i
high advisory

Disabling LSA Protection via Registry Modification

Adversaries may modify the RunAsPPL registry key to disable LSA protection, which prevents nonprotected processes from reading memory and injecting code, potentially leading to credential access.

Elastic Defend +3 defense-evasion windows registry
2r 1t
low advisory

Component Object Model (COM) Hijacking via Registry Modification

Adversaries may establish persistence by executing malicious content triggered by hijacked references to COM objects through Component Object Model (COM) hijacking via registry modification on Windows systems.

Elastic Defend +9 persistence com-hijacking windows registry defense-evasion privilege-escalation
2r 4t
high advisory

Windows Defender Health Check Interval Modification

This analytic detects modifications to the Windows registry, specifically targeting the `ServiceKeepAlive` value, to impair Windows Defender's ability to perform timely health checks, potentially leading to a vulnerable system state.

Splunk Enterprise +3 windows registry defender defense-evasion threat
2r
medium advisory

Persistence via LSA Security Support Provider Registry Modification

Adversaries may establish persistence by modifying the Windows Security Support Provider (SSP) configuration in the registry, allowing malicious code to load during system startup.

Windows persistence registry
2r 2t
high advisory

Persistence via Hidden Run Key

Adversaries achieve persistence by creating hidden, null-terminated registry keys within common Run key locations, evading standard system utilities.

Windows persistence registry defense-evasion
2r 4t
medium advisory

MS Office Macro Security Registry Modifications

Attackers may modify Microsoft Office registry settings related to macro security (AccessVBOM, VbaWarnings) to disable security warnings, enabling malicious macros for persistence and further compromise.

Microsoft Office office macro registry defense-evasion windows
2r 2t
medium advisory

LSASS Shtinkering Detection via Full User-Mode Dump Configuration

Detection of the enabling of full user-mode dumps system-wide, a setting change leveraged in LSASS Shtinkering attacks to dump LSASS process memory and steal credentials.

Windows credential-access lsass registry
2r 2t
medium advisory

Image File Execution Options (IFEO) Injection for Persistence and Defense Evasion

Adversaries abuse Image File Execution Options (IFEO) in the Windows Registry by modifying Debugger or MonitorProcess keys to intercept legitimate file executions, enabling persistence and defense evasion.

Windows persistence defense-evasion registry
2r 3t