WINEKEY Registry Modification

 Original Source: [Sigma source]
Title: WINEKEY Registry Modification
Status: test
Description:Detects potential malicious modification of run keys by winekey or team9 backdoor
References:
  -https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html
Author: omkar72
Date: 2020-10-30
modified:2021-11-27
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
    TargetObject|endswith: 'Software\Microsoft\Windows\CurrentVersion\Run\Backup Mgr'
  condition:selection
Falsepositives:
  -Unknown
Level: high