This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
ClickOnce Trust Prompt Tampering
Original Source:
[Sigma source]
Title:
ClickOnce Trust Prompt Tampering
Status:
test
Description:
Detects changes to the ClickOnce trust prompt registry key in order to enable an installation from different locations such as the Internet.
References:
-https://posts.specterops.io/less-smartscreen-more-caffeine-ab-using-clickonce-for-trusted-code-execution-1446ea8051c5
-https://learn.microsoft.com/en-us/visualstudio/deployment/how-to-configure-the-clickonce-trust-prompt-behavior
Author:
@SerkinValery, Nasreddine Bencherchali (Nextron Systems)
Date:
2023-06-12
modified:
2023-08-17
Tags:
-'attack.persistence'
-'attack.defense-impairment'
-'attack.t1112'
Logsource:
category: registry_set
product: windows
Detection:
selection:
TargetObject|contains
:
'\SOFTWARE\MICROSOFT\.NETFramework\Security\TrustManager\PromptingLevel\'
TargetObject|endswith
:
-'\Internet'
-'\LocalIntranet'
-'\MyComputer'
-'\TrustedSites'
-'\UntrustedSites'
Details
:
'Enabled'
condition
:
selection
Falsepositives:
-Legitimate internal requirements.
Level:
medium