PowerShell VBScript RegWrite Registry Modification Attempts

Identifies PowerShell commands embedding VBScript Wscript.shell .RegWrite to modify Windows registry values.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_script
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-08-13
Updated
2026-07-31
title: PowerShell VBScript RegWrite Registry Modification Attempts
id: 3580787a-d668-491f-9459-f6442ac55610
related:
  - id: 921aa10f-2e74-4cca-9498-98f9ca4d6fdf
    type: similar
  - id: 7f4c43f9-b1a5-4c7d-b24a-b41bf3a3ebf2
    type: similar
  - id: 2a0a169d-cc66-43ce-9ae2-6e678e54e46a
    type: derived
status: experimental
description: This rule flags PowerShell script content that constructs a VBScript shell object (CreateObject("Wscript.shell")) and calls the VBScript RegWrite method to modify registry values. This matters because attackers can perform registry changes without using common registry utilities or native registry cmdlets, which may help evade standard detections. Telemetry is based on PowerShell ScriptBlockText matches for CreateObject, Wscript.shell, and RegWrite within the same script block.
references:
  - https://www.linkedin.com/posts/mauricefielenbach_livingofftheland-redteam-persistence-activity-7344801774182051843-TE00/
  - https://www.nextron-systems.com/2025/07/29/detecting-the-most-popular-mitre-persistence-method-registry-run-keys-startup-folder/
  - https://detect.fyi/hunting-fileless-malware-in-the-windows-registry-1339ccde00ad
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_vbscript_registry_modification.yml
date: 2025-08-13
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
tags:
  - attack.persistence
  - attack.execution
  - attack.defense-impairment
  - attack.t1112
  - attack.t1059.005
logsource:
  category: ps_script
  product: windows
detection:
  selection:
    ScriptBlockText|contains|all:
      - CreateObject
      - Wscript.shell
      - .RegWrite
  condition: selection
falsepositives:
  - Some legitimate admin or install scripts may use these processes for registry modifications.
level: medium
license: DRL-1.1