Registry Explorer Policy Modification

 Original Source: [Sigma source]
Title: Registry Explorer Policy Modification
Status: test
Description:Detects registry modifications that disable internal tools or functions in explorer (malware like Agent Tesla uses this technique)
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md
Author: frack113
Date: 2022-03-18
modified:2023-08-17
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection_set_1:
    TargetObject|endswith:
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogOff'
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop'
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun'
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind'
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel'
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu'
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose'
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskbar'
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyDocuments'
      -'SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoTrayContextMenu'

    Details: 'DWORD (0x00000001)'
  condition:selection_set_1
Falsepositives:
  -Legitimate admin script
Level: medium