SafeBoot Registry Key Deleted Via Reg.EXE

 Original Source: [Sigma source]
Title: SafeBoot Registry Key Deleted Via Reg.EXE
Status: test
Description:Detects execution of "reg.exe" commands with the "delete" flag on safe boot registry keys. Often used by attacker to prevent safeboot execution of security products
References:
  -https://www.trendmicro.com/en_us/research/22/e/avoslocker-ransomware-variant-abuses-driver-file-to-disable-anti-Virus-scans-log4shell.html
Author: Nasreddine Bencherchali (Nextron Systems), Tim Shelton
Date: 2022-08-08
modified:2023-02-04
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'reg.exe' OriginalFileName:'reg.exe'   selection_delete:
    CommandLine|contains|all:
      -' delete '
      -'\SYSTEM\CurrentControlSet\Control\SafeBoot'

  condition:all of selection_*
Falsepositives:
  -Unlikely
Level: high