Possible System Language Enumeration through Reg.Exe (via process_creation)
This rule detects the use of Reg.Exe to query system language settings. Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions, or avoid targeting certain locales to evade detection.
SigmamediumWindowsv1
sigma
possible-system-language-enumeration-through-reg-exe-via-process-creation
title: Possible System Language Enumeration through Reg.Exe (via process_creation)
id: 1f065595-bbeb-508d-a29c-dce93a05ca58
status: stable
description: This rule detects the use of Reg.Exe to query system language settings. Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions, or avoid targeting certain locales to evade detection.
references:
- https://attack.mitre.org/techniques/T1614/001/
- https://scythe.io/threat-thursday/threatthursday-darkside-ransomware
author: Huntrule Team
date: 2026-02-17
tags:
- attack.discovery
- attack.t1614.001
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: '\reg.exe'
- OriginalFileName: 'reg.exe'
selection_cli:
CommandLine|contains|all:
- 'query'
- 'Control\Nls\Language'
condition: all of selection_*
falsepositives:
- Unknown
level: medium
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_reg_system_language_discovery/info.yml
simulation:
- type: atomic-red-team
name: Discover System Language by Registry Query
technique: T1614.001
atomic_guid: 631d4cf1-42c9-4209-8fe9-6bd4de9421be
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.