This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Windows Hypervisor Enforced Code Integrity Disabled
Original Source:
[Sigma source]
Title:
Windows Hypervisor Enforced Code Integrity Disabled
Status:
test
Description:
Detects changes to the HypervisorEnforcedCodeIntegrity registry key and the "Enabled" value being set to 0 in order to disable the Hypervisor Enforced Code Integrity feature. This allows an attacker to load unsigned and untrusted code to be run in the kernel
References:
-https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/
-https://github.com/redcanaryco/atomic-red-team/blob/04e487c1828d76df3e834621f4f893ea756d5232/atomics/T1562.001/T1562.001.md#atomic-test-43---disable-hypervisor-enforced-code-integrity-hvci
Author:
Nasreddine Bencherchali (Nextron Systems), Anish Bogati
Date:
2023-03-14
modified:
2024-07-05
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
category: registry_set
product: windows
Detection:
selection:
TargetObject|endswith
:
-'\Control\DeviceGuard\HypervisorEnforcedCodeIntegrity'
-'\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity\Enabled'
-'\Microsoft\Windows\DeviceGuard\HypervisorEnforcedCodeIntegrity'
Details
:
'DWORD (0x00000000)'
condition
:
selection
Falsepositives:
-Legitimate system administration tasks that require disabling HVCI for troubleshooting purposes when certain drivers or applications are incompatible with it.
Level:
high