Security Service Disabled Via Reg.EXE

 Original Source: [Sigma source]
Title: Security Service Disabled Via Reg.EXE
Status: test
Description:Detects execution of "reg.exe" to disable security services such as Windows Defender.
References:
  -https://twitter.com/JohnLaTwC/status/1415295021041979392
  -https://github.com/gordonbay/Windows-On-Reins/blob/e587ac7a0407847865926d575e3c46f68cf7c68d/wor.ps1
  -https://vms.drweb.fr/virus/?i=24144899
  -https://bidouillesecurity.com/disable-windows-defender-in-powershell/
Author: Florian Roth (Nextron Systems), John Lambert (idea), elhoim
Date: 2021-07-14
modified:2023-06-05
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_reg_add:
    CommandLine|contains|all:
      -'reg'
      -'add'

  selection_cli_reg_start:
    CommandLine|contains|all:
      -'d 4'
      -'v Start'

    CommandLine|contains:
      -'\AppIDSvc'
      -'\MsMpSvc'
      -'\NisSrv'
      -'\SecurityHealthService'
      -'\Sense'
      -'\UsoSvc'
      -'\WdBoot'
      -'\WdFilter'
      -'\WdNisDrv'
      -'\WdNisSvc'
      -'\WinDefend'
      -'\wscsvc'
      -'\wuauserv'

  condition:all of selection_*
Falsepositives:
  -Unlikely
Level: high