Possible PendingFileRenameOperations Manipulation (via registry_set)
This rule detects changes to the "PendingFileRenameOperations" registry key from uncommon or anomalous images locations to stage currently used files for rename or deletion after reboot.
SigmamediumWindowsv1
sigma
possible-pendingfilerenameoperations-manipulation-via-registry-set
title: Possible PendingFileRenameOperations Manipulation (via registry_set)
id: 8ef3b6d8-c69a-54d3-9f97-ca24e6b49fa9
status: stable
description: This rule detects changes to the "PendingFileRenameOperations" registry key from uncommon or anomalous images locations to stage currently used files for rename or deletion after reboot.
references:
- https://attack.mitre.org/techniques/T1036/003/
- https://any.run/report/3ecd4763ffc944fdc67a9027e459cd4f448b1a8d1b36147977afaf86bbf2a261/64b0ba45-e7ce-423b-9a1d-5b4ea59521e6
- https://devblogs.microsoft.com/scripting/determine-pending-reboot-statuspowershell-style-part-1/
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-2000-server/cc960241(v=technet.10)?redirectedfrom=MSDN
- https://www.trendmicro.com/en_us/research/21/j/purplefox-adds-new-backdoor-that-uses-websockets.html
- https://www.trendmicro.com/en_us/research/19/i/purple-fox-fileless-malware-with-rookit-component-delivered-by-rig-exploit-kit-now-abuses-powershell.html
author: Huntrule Team
date: 2026-02-28
tags:
- attack.stealth
- attack.t1036.003
logsource:
category: registry_set
product: windows
detection:
selection_main:
TargetObject|contains: '\CurrentControlSet\Control\Session Manager\PendingFileRenameOperations'
selection_susp_paths:
Image|contains: '\Users\Public\'
selection_susp_images:
Image|endswith:
- '\reg.exe'
- '\regedit.exe'
condition: selection_main and 1 of selection_susp_*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.