LanmanServer MaxMpxCt Registry Modification for Lateral Movement Preparation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-01
Updated
2026-10-01

ATT&CK techniques

Persistence → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects modification of the LanmanServer MaxMpxCt registry value, which raises the maximum outstanding SMB requests to support high-volume lateral spreading. Huntress observed BlackCat affiliates tuning this value before mass deployment across a network. This uncommon server parameter change is a preparation step for scaled lateral movement and ransomware distribution.

Related detections9 linkedT1112 — drag to rearrange
Malicious Restricted Admin Mode Enabled for Pass-the-Hash RDP
Malicious Windows Defender Service Disable via Registry
Suspicious RDP Enablement via fDenyTSConnections Registry Modification
Malicious WDigest UseLogonCredential Enablement for Cleartext Credentials
Suspicious RDP Enablement via fDenyTSConnections Registry Modification [Huntress] #2
Malicious Winos 4.0 Configuration and Shellcode Storage in Registry (via registry_set)
Suspicious Service ImagePath Pointing to ShieldNetWork Driver via Registry
Suspicious CredSSP Encryption Oracle Remediation Weakening via Registry (via registry_set)
Malicious Kong RAT Configuration Registry Keys
LanmanServer MaxMpxCt Registry Modification for Lateral Movement Preparation
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.