Disable Windows Event Logging Via Registry

 Original Source: [Sigma source]
Title: Disable Windows Event Logging Via Registry
Status: test
Description:Detects tampering with the "Enabled" registry key in order to disable Windows logging of a Windows event channel
References:
  -https://twitter.com/WhichbufferArda/status/1543900539280293889
  -https://github.com/DebugPrivilege/CPP/blob/c39d365617dbfbcb01fffad200d52b6239b2918c/Windows%20Defender/RestoreDefenderConfig.cpp
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-04
modified:2024-03-25
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685.001'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains: '\Microsoft\Windows\CurrentVersion\WINEVT\Channels\'
    TargetObject|endswith: '\Enabled'
    Details: 'DWORD (0x00000000)'
  filter_main_wevutil:
    Image: 'C:\Windows\system32\wevtutil.exe'
  filter_main_iis:
    Image|startswith: 'C:\Windows\winsxs\'
    Image|endswith: '\TiWorker.exe'
  filter_main_svchost:
    Image: 'C:\Windows\System32\svchost.exe'
    TargetObject|contains:
      -'\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-FileInfoMinifilter'
      -'\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ASN1\'
      -'\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-AppCompat\'
      -'\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Runtime\Error\'
      -'\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-CAPI2/Operational\'

  filter_main_trusted_installer:
    Image: 'C:\Windows\servicing\TrustedInstaller.exe'
    TargetObject|contains: '\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Compat-Appraiser'
  filter_optional_empty:
    Image: ''
  filter_optional_null:
    Image: 'None'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Rare falsepositives may occur from legitimate administrators disabling specific event log for troubleshooting
Level: high