Registry Persistence via Explorer Run Key

 Original Source: [Sigma source]
Title: Registry Persistence via Explorer Run Key
Status: test
Description:Detects a possible persistence mechanism using RUN key for Windows Explorer and pointing to a suspicious folder
References:
  -https://researchcenter.paloaltonetworks.com/2018/07/unit42-upatre-continues-evolve-new-anti-analysis-techniques/
Author: Florian Roth (Nextron Systems), oscd.community
Date: 2018-07-18
modified:2023-12-11
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1547.001'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|endswith: '\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run'
    Details|contains:
      -':\$Recycle.bin\'
      -':\ProgramData\'
      -':\Temp\'
      -':\Users\Default\'
      -':\Users\Public\'
      -':\Windows\Temp\'
      -'\AppData\Local\Temp\'

  condition:selection
Falsepositives:
  -Unknown
Level: high