This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Autorun Registry Modified via WMI
Original Source:
[Sigma source]
Title:
Suspicious Autorun Registry Modified via WMI
Status:
experimental
Description:
Detects suspicious activity where the WMIC process is used to create an autorun registry entry via reg.exe, which is often indicative of persistence mechanisms employed by malware.
References:
-Internal Research
-https://github.com/HackTricks-wiki/hacktricks/blob/e4c7b21b8f36c97c35b7c622732b38a189ce18f7/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md
Author:
Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2025-02-17
modified:
None
Tags:
-'attack.privilege-escalation'
-'attack.execution'
-'attack.persistence'
-'attack.t1547.001'
-'attack.t1047'
Logsource:
category: process_creation
product: windows
Detection:
selection_execution_img:
Image|endswith
:
'\wmic.exe'
OriginalFileName
:
'wmic.exe'
ParentImage|endswith
:
'\wmiprvse.exe'
selection_execution_cmd:
CommandLine|contains|all
:
-'reg'
-' add '
CommandLine|contains
:
-'\Software\Microsoft\Windows\CurrentVersion\Run'
-'\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run'
-'\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run'
selection_suspicious_paths_1:
CommandLine|contains
:
-':\Perflogs'
-':\ProgramData''
-':\Windows\Temp'
-':\Temp'
-'\AppData\Local\Temp'
-'\AppData\Roaming'
-':\$Recycle.bin'
-':\Users\Default'
-':\Users\public'
-'%temp%'
-'%tmp%'
-'%Public%'
-'%AppData%'
selection_suspicious_paths_user_1:
CommandLine|contains
:
':\Users\'
selection_suspicious_paths_user_2:
CommandLine|contains
:
-'\Favorites'
-'\Favourites'
-'\Contacts'
-'\Music'
-'\Pictures'
-'\Documents'
-'\Photos'
condition
:
all of selection_execution_* and (selection_suspicious_paths_1 or (all of selection_suspicious_paths_user_*))
Falsepositives:
-Legitimate administrative activity or software installations
Level:
high