Security Event Logging Disabled via MiniNt Registry Key - Process

 Original Source: [Sigma source]
Title: Security Event Logging Disabled via MiniNt Registry Key - Process
Status: experimental
Description:Detects attempts to disable security event logging by adding the `MiniNt` registry key. This key is used to disable the Windows Event Log service, which collects and stores event logs from the operating system and applications. Adversaries may want to disable this service to prevent logging of security events that could be used to detect their activities.
References:
  -https://www.hackingarticles.in/defense-evasion-windows-event-logging-t1562-002/
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-04-09
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1685.001'
  • -'attack.t1112'
  • -'car.2022-03-001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_reg_img:
Image|endswith:'\reg.exe' OriginalFileName:'reg.exe'   selection_reg_cmd:
    CommandLine|contains|all:
      -' add '
      -'\SYSTEM\CurrentControlSet\Control\MiniNt'

  selection_powershell_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\powershell_ise.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_powershell_cmd1:
    CommandLine|contains:
      -'New-Item '
      -'ni '

  selection_powershell_cmd2:
    CommandLine|contains: '\SYSTEM\CurrentControlSet\Control\MiniNt'
  condition:all of selection_reg_* or all of selection_powershell_*
Falsepositives:
  -Highly Unlikely
Level: high