Critical Hive In Suspicious Location Access Bits Cleared

 Original Source: [Sigma source]
Title: Critical Hive In Suspicious Location Access Bits Cleared
Status: test
Description:Detects events from the Kernel-General ETW indicating that the access bits of a hive with a system like hive name located in the temp directory have been reset. This occurs when an application tries to access a hive and the hive has not be recognized since the last 7 days (by default). Registry hive dumping utilities such as QuarksPwDump were seen emitting this behavior.
References:
  -https://github.com/nasbench/Misc-Research/blob/b20da2336de0f342d31ef4794959d28c8d3ba5ba/ETW/Microsoft-Windows-Kernel-General.md
Author: Florian Roth (Nextron Systems)
Date: 2017-05-15
modified:2024-01-18
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
Logsource:
  • product: windows
  • service: system
Detection:
  selection:
    EventID: '16'
    Provider_Name: 'Microsoft-Windows-Kernel-General'
    HiveName|contains:
      -'\Temp\SAM'
      -'\Temp\SECURITY'

  condition:selection
Falsepositives:
  -Unknown
Level: high