Potential Persistence Via Custom Protocol Handler

 Original Source: [Sigma source]
Title: Potential Persistence Via Custom Protocol Handler
Status: test
Description:Detects potential persistence activity via the registering of a new custom protocole handlers. While legitimate applications register protocole handlers often times during installation. And attacker can abuse this by setting a custom handler to be used as a persistence mechanism.
References:
  -https://ladydebug.com/blog/2019/06/21/custom-protocol-handler-cph/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-05-30
modified:2023-05-12
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|startswith: 'HKCR\'
    Details|startswith: 'URL:'
  filter_main_ms_trusted:
    Details|startswith: 'URL:ms-'
  filter_main_generic_locations:
    Image|startswith:
      -'C:\Program Files (x86)'
      -'C:\Program Files\'
      -'C:\Windows\System32\'
      -'C:\Windows\SysWOW64\'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Many legitimate applications can register a new custom protocol handler. Additional filters needs to applied according to your environment.
Level: medium