Direct Autorun Keys Modification

 Original Source: [Sigma source]
Title: Direct Autorun Keys Modification
Status: test
Description:Detects direct modification of autostart extensibility point (ASEP) in registry using reg.exe.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
  -https://github.com/HackTricks-wiki/hacktricks/blob/e4c7b21b8f36c97c35b7c622732b38a189ce18f7/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md
Author: Victor Sergeev, Daniil Yugoslavskiy, oscd.community, Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2019-10-25
modified:2026-01-05
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\reg.exe' OriginalFileName:'reg.exe'   selection_cli_add:
    CommandLine|contains: 'add'
  selection_cli_keys:
    CommandLine|contains:
      -'\software\Microsoft\Windows\CurrentVersion\Run'
      -'\software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run'
      -'\software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run'
      -'\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit'
      -'\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell'
      -'\software\Microsoft\Windows NT\CurrentVersion\Windows'
      -'\system\CurrentControlSet\Control\SafeBoot\AlternateShell'

  condition:all of selection_*
Falsepositives:
  -Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reasons.
  -Legitimate administrator sets up autorun keys for legitimate reasons.
  -Discord
Level: medium