Suspicious Reg Add BitLocker

 Original Source: [Sigma source]
Title: Suspicious Reg Add BitLocker
Status: test
Description:Detects suspicious addition to BitLocker related registry keys via the reg.exe utility
References:
  -https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/
Author: frack113
Date: 2021-11-15
modified:2022-09-09
Tags:
  • -'attack.impact'
  • -'attack.t1486'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'REG'
      -'ADD'
      -'\SOFTWARE\Policies\Microsoft\FVE'
      -'/v'
      -'/f'

    CommandLine|contains:
      -'EnableBDEWithNoTPM'
      -'UseAdvancedStartup'
      -'UseTPM'
      -'UseTPMKey'
      -'UseTPMKeyPIN'
      -'RecoveryKeyMessageSource'
      -'UseTPMPIN'
      -'RecoveryKeyMessage'

  condition:selection
Falsepositives:
  -Unlikely
Level: high