This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential PendingFileRenameOperations Tampering
Original Source:
[Sigma source]
Title:
Potential PendingFileRenameOperations Tampering
Status:
test
Description:
Detect changes to the "PendingFileRenameOperations" registry key from uncommon or suspicious images locations to stage currently used files for rename or deletion after reboot.
References:
-https://any.run/report/3ecd4763ffc944fdc67a9027e459cd4f448b1a8d1b36147977afaf86bbf2a261/64b0ba45-e7ce-423b-9a1d-5b4ea59521e6
-https://devblogs.microsoft.com/scripting/determine-pending-reboot-statuspowershell-style-part-1/
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-2000-server/cc960241(v=technet.10)?redirectedfrom=MSDN
-https://www.trendmicro.com/en_us/research/21/j/purplefox-adds-new-backdoor-that-uses-websockets.html
-https://www.trendmicro.com/en_us/research/19/i/purple-fox-fileless-malware-with-rookit-component-delivered-by-rig-exploit-kit-now-abuses-powershell.html
Author:
frack113
Date:
2023-01-27
modified:
2025-10-07
Tags:
-'attack.stealth'
-'attack.t1036.003'
Logsource:
category: registry_set
product: windows
Detection:
selection_main:
TargetObject|contains
:
'\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations'
selection_susp_paths:
Image|contains
:
'\Users\Public\'
selection_susp_images:
Image|endswith
:
-'\reg.exe'
-'\regedit.exe'
condition
:
selection_main and 1 of selection_susp_*
Falsepositives:
-Installers and updaters may set currently in use files for rename or deletion after a reboot.
Level:
medium