This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Shell Open Registry Keys Manipulation
Original Source:
[Sigma source]
Title:
Shell Open Registry Keys Manipulation
Status:
test
Description:
Detects manipulation of shell open command registry keys such as "ms-settings" and "exefile", which are commonly abused to achieve UAC bypass (e.g. via fodhelper.exe) or establish persistence through file association hijacking.
References:
-https://github.com/hfiref0x/UACME
-https://winscripting.blog/2017/05/12/first-entry-welcome-and-uac-bypass/
-https://github.com/RhinoSecurityLabs/Aggressor-Scripts/tree/master/UACBypass
-https://tria.ge/211119-gs7rtshcfr/behavioral2 [Lokibot sample from Nov 2021]
Author:
Christian Burkard (Nextron Systems)
Date:
2021-08-30
modified:
2026-08-27
Tags:
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.t1548.002'
-'attack.t1546.001'
Logsource:
category: registry_event
product: windows
Detection:
selection_1:
EventType
:
'SetValue'
TargetObject|endswith
:
'Classes\ms-settings\shell\open\command\SymbolicLinkValue'
Details|contains
:
'\Software\Classes\{'
selection_2:
TargetObject|endswith
:
'Classes\ms-settings\shell\open\command\DelegateExecute'
selection_3:
EventType
:
'SetValue'
TargetObject|endswith
:
-'Classes\ms-settings\shell\open\command\(Default)'
-'Classes\exefile\shell\open\command\(Default)'
filter_main_empty:
Details
:
'(Empty)'
filter_main_default_com:
Details
:
-'{4813071a-41ad-44a2-9835-886d2f63ca30}'
-'{A56A841F-E974-45C1-8001-7E3F8A085917}'
-'{4ED3A719-CEA8-4BD9-910D-E252F997AFC2}'
-'{BFEC0C93-0B7D-4F2C-B09C-AFFFC4BDAE78}'
condition
:
1 of selection_* and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
high