Windows AMSI Related Registry Tampering Via CommandLine

 Original Source: [Sigma source]
Title: Windows AMSI Related Registry Tampering Via CommandLine
Status: experimental
Description:Detects tampering of AMSI (Anti-Malware Scan Interface) related registry values via command line tools such as reg.exe or PowerShell. AMSI provides a generic interface for applications and services to integrate with antimalware products. Adversaries may disable AMSI to evade detection of malicious scripts and code execution.
References:
  -https://github.com/arttoolkit/arttoolkit.github.io/blob/16d6230d009e58fd6f773f5317fd4d14c1f26004/_wadcoms/AMSI-Bypass-Jscript_amsienable.md
  -https://mostafayahiax.medium.com/hunting-for-amsi-bypassing-methods-9886dda0bf9d
  -https://www.mdsec.co.uk/2019/02/macros-and-more-with-sharpshooter-v2-0/
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-12-25
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_key:
    CommandLine|contains|all:
      -'\Software\Microsoft\Windows Script\Settings'
      -'AmsiEnable'

  selection_reg_img:
Image|endswith:'\reg.exe' OriginalFileName:'reg.exe'   selection_reg_cmd:
    CommandLine|contains: 'add'
  selection_powershell_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_powershell_cmd:
    CommandLine|contains:
      -'Set-ItemProperty'
      -'New-ItemProperty'
      -'sp '

  condition:selection_key and (all of selection_powershell_* or all of selection_reg_*)
Falsepositives:
  -Unknown
Level: high