Modification of IE Registry Settings

 Original Source: [Sigma source]
Title: Modification of IE Registry Settings
Status: test
Description:Detects modification of the registry settings used for Internet Explorer and other Windows components that use these settings. An attacker can abuse this registry key to add a domain to the trusted sites Zone or insert JavaScript for persistence
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-4---add-domain-to-trusted-sites-zone
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-5---javascript-in-registry
Author: frack113
Date: 2022-01-22
modified:2025-10-22
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection_domains:
    TargetObject|contains: '\Software\Microsoft\Windows\CurrentVersion\Internet Settings'
  filter_main_dword:
    Details|startswith: 'DWORD'
  filter_main_null:
    Details: 'None'
  filter_main_office:
    Details:
      -'Cookie:'
      -'Visited:'
      -'(Empty)'

  filter_main_path:
    TargetObject|contains:
      -'\Cache'
      -'\ZoneMap'
      -'\WpadDecision'

  filter_main_binary:
    Details: 'Binary Data'
  filter_optional_accepted_documents:
    TargetObject|contains: '\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents'
  condition:selection_domains and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: low