This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Disabling Windows Defender WMI Autologger Session via Reg.exe
Original Source:
[Sigma source]
Title:
Disabling Windows Defender WMI Autologger Session via Reg.exe
Status:
experimental
Description:
Detects the use of reg.exe to disable the Event Tracing for Windows (ETW) Autologger session for Windows Defender API and Audit events. By setting the 'Start' value to '0' for the 'DefenderApiLogger' or 'DefenderAuditLogger' session, an attacker can prevent these critical security events from being logged, effectively blinding monitoring tools that rely on this data. This is a powerful defense evasion technique.
References:
-https://research.splunk.com/endpoint/76406a0f-f5e0-4167-8e1f-337fdc0f1b0c/
-https://docs.microsoft.com/en-us/windows/win32/etw/configuring-and-starting-an-autologger-session
-https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
-https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/
-https://www.binarly.io/blog/design-issues-of-modern-edrs-bypassing-etw-based-solutions
Author:
Matt Anderson (Huntress)
Date:
2025-07-09
modified:
None
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\reg.exe'
OriginalFileName
:
'reg.exe'
selection_reg_path:
CommandLine|contains
:
-'\Control\WMI\Autologger\DefenderApiLogger\Start'
-'\Control\WMI\Autologger\DefenderAuditLogger\Start'
selection_reg_add:
CommandLine|contains|all
:
-'add'
-'0'
filter_main_enable:
CommandLine|contains
:
'0x00000001'
condition
:
all of selection_* and not 1 of filter_main_*
Falsepositives:
-Highly unlikely
Level:
high