Tag
Modification of WDigest UseLogonCredential Registry Key
1 rule 2 TTPsAdversaries modify the WDigest UseLogonCredential registry key to downgrade credential protection and enable the storage of clear-text passwords in memory for exfiltration via LSASS.
Detection of Windows Service Binaries in Suspicious Directories
1 rule 1 TTPAdversaries often achieve persistence by registering malicious Windows services with binaries located in writeable or temp directories to evade detection.
Detection of .NET Framework ETW Evasion via Registry Modification
1 rule 1 TTPAttackers can disable .NET Framework Event Tracing for Windows (ETW) by modifying registry environment variables, effectively blinding EDR solutions and security telemetry to malicious managed-code execution.
Windows Defender Signature Retirement Disabled via Registry Modification
2 rules 1 TTPAn attacker disables Windows Defender's signature retirement feature by modifying a registry key, potentially reducing its effectiveness in detecting threats by allowing older, less relevant signatures to persist.
Windows Defender Network Protection Disabled via Registry Modification
2 rules 1 TTPThis analytic detects modifications to the Windows registry to disable Windows Defender Network Protection, potentially leaving the system vulnerable to network-based threats.
Windows Defender Quick Scan Interval Modification
2 rules 1 TTPDetection of modifications to the Windows registry that change the Windows Defender Quick Scan Interval, potentially impairing its ability to detect malware promptly.