RunMRU Registry Key Deletion

 Original Source: [Sigma source]
Title: RunMRU Registry Key Deletion
Status: experimental
Description:Detects deletion of the RunMRU registry key, which stores the history of commands executed via the Run dialog. In the clickfix techniques, the phishing lures instruct users to open a run dialog through (Win + R) and execute malicious commands. Adversaries may delete this key to cover their tracks after executing commands.
References:
  -https://www.zscaler.com/blogs/security-research/coldriver-updates-arsenal-baitswitch-and-simplefix
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-09-25
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1070.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\reg.exe' OriginalFileName:'reg.exe'   selection_cli:
    CommandLine|contains|all:
      -' del'
      -'\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high