Exports Critical Registry Keys To a File

 Original Source: [Sigma source]
Title: Exports Critical Registry Keys To a File
Status: test
Description:Detects the export of a crital Registry key to a file.
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Regedit/
  -https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f
Author: Oddvar Moe, Sander Wiebing, oscd.community
Date: 2020-10-12
modified:2024-03-13
Tags:
  • -'attack.exfiltration'
  • -'attack.discovery'
  • -'attack.t1012'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\regedit.exe' OriginalFileName:'REGEDIT.EXE'   selection_cli_1:
    CommandLine|contains|windash: ' -E '
  selection_cli_2:
    CommandLine|contains:
      -'hklm'
      -'hkey_local_machine'

  selection_cli_3:
    CommandLine|endswith:
      -'\system'
      -'\sam'
      -'\security'

  condition:all of selection_*
Falsepositives:
  -Dumping hives for legitimate purpouse i.e. backup or forensic investigation
Level: high