Windows Hypervisor Enforced Code Integrity Disabled

 Original Source: [Sigma source]
Title: Windows Hypervisor Enforced Code Integrity Disabled
Status: test
Description:Detects changes to the HypervisorEnforcedCodeIntegrity registry key and the "Enabled" value being set to 0 in order to disable the Hypervisor Enforced Code Integrity feature. This allows an attacker to load unsigned and untrusted code to be run in the kernel
References:
  -https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/
  -https://github.com/redcanaryco/atomic-red-team/blob/04e487c1828d76df3e834621f4f893ea756d5232/atomics/T1562.001/T1562.001.md#atomic-test-43---disable-hypervisor-enforced-code-integrity-hvci
Author: Nasreddine Bencherchali (Nextron Systems), Anish Bogati
Date: 2023-03-14
modified:2024-07-05
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|endswith:
      -'\Control\DeviceGuard\HypervisorEnforcedCodeIntegrity'
      -'\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity\Enabled'
      -'\Microsoft\Windows\DeviceGuard\HypervisorEnforcedCodeIntegrity'

    Details: 'DWORD (0x00000000)'
  condition:selection
Falsepositives:
  -Legitimate system administration tasks that require disabling HVCI for troubleshooting purposes when certain drivers or applications are incompatible with it.
Level: high