Potential Registry Persistence Attempt Via DbgManagedDebugger

 Original Source: [Sigma source]
Title: Potential Registry Persistence Attempt Via DbgManagedDebugger
Status: test
Description:Detects the addition of the "Debugger" value to the "DbgManagedDebugger" key in order to achieve persistence. Which will get invoked when an application crashes
References:
  -https://www.hexacorn.com/blog/2013/09/19/beyond-good-ol-run-key-part-4/
  -https://github.com/last-byte/PersistenceSniper
Author: frack113
Date: 2022-08-07
modified:2023-08-17
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|endswith: '\Microsoft\.NETFramework\DbgManagedDebugger'
  filter:
    Details: '"C:\Windows\system32\vsjitdebugger.exe" PID %d APPDOM %d EXTEXT "%s" EVTHDL %d'
  condition:selection and not filter
Falsepositives:
  -Legitimate use of the key to setup a debugger. Which is often the case on developers machines
Level: medium