Title:
Potential Persistence Via Custom Protocol Handler
Status:
test
Description:Detects potential persistence activity via the registering of a new custom protocole handlers. While legitimate applications register protocole handlers often times during installation. And attacker can abuse this by setting a custom handler to be used as a persistence mechanism.
References:
-https://ladydebug.com/blog/2019/06/21/custom-protocol-handler-cph/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-05-30
modified:2023-05-12
Tags:
- -'attack.persistence'
- -'attack.defense-impairment'
- -'attack.t1112'
Logsource:
- category: registry_set
- product: windows
Detection:
selection:
TargetObject|startswith:
'HKCR\'
Details|startswith:
'URL:'
filter_main_ms_trusted:
Details|startswith:
'URL:ms-'
filter_main_generic_locations:
Image|startswith:
-'C:\Program Files (x86)'
-'C:\Program Files\'
-'C:\Windows\System32\'
-'C:\Windows\SysWOW64\'
condition:
selection and not 1 of filter_main_*
Falsepositives:
-Many legitimate applications can register a new custom protocol handler. Additional filters needs to applied according to your environment.
Level:
medium