Blackbyte Ransomware Registry

 Original Source: [Sigma source]
Title: Blackbyte Ransomware Registry
Status: test
Description:BlackByte set three different registry values to escalate privileges and begin setting the stage for lateral movement and encryption
References:
  -https://redcanary.com/blog/blackbyte-ransomware/?utm_source=twitter&utm_medium=social
  -https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/blackbyte-ransomware-pt-1-in-depth-analysis/
Author: frack113
Date: 2022-01-24
modified:2023-08-17
Tags:
  • -'attack.defense-evasion'
  • -'attack.t1112'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject:
      -'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy'
      -'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLinkedConnections'
      -'HKLM\SYSTEM\CurrentControlSet\Control\FileSystem\LongPathsEnabled'

    Details: 'DWORD (0x00000001)'
  condition:selection
Falsepositives:
  -Unknown
Level: high