Title:Registry Modification of MS-settings Protocol Handler Status:test Description:Detects registry modifications to the 'ms-settings' protocol handler, which is frequently targeted for UAC bypass or persistence.
Attackers can modify this registry to execute malicious code with elevated privileges by hijacking the command execution path.
References: -https://thedfirreport.com/2021/12/13/diavol-ransomware/ -https://www.trendmicro.com/en_us/research/25/f/water-curse.html Author: frack113, Swachchhanda Shrawan Poudel (Nextron Systems) Date: 2021-12-20 modified:2026-01-24 Tags:
selection_cli_key: CommandLine|contains:
'\ms-settings\shell\open\command' condition:(all of selection_reg_* or all of selection_pwsh_*) and selection_cli_key Falsepositives:
-Unknown Level:medium