RPC Firewall detects remote registry modification via Microsoft RRP interface calls (OpNum 6/7/8/13/18/19/21/22/23/35)
Alerts on RPC Firewall registry-interface RPC calls (EventID 3) with OpNums tied to remote registry modification.
FreeUnreviewedSigmahighv1
rpc-firewall-detects-remote-registry-modification-via-microsoft-rrp-interface-ca-35c55673
title: RPC Firewall detects remote registry modification via Microsoft RRP interface calls (OpNum 6/7/8/13/18/19/21/22/23/35)
id: 8f70e8bc-2aa3-4882-96ff-611def2df62b
status: test
description: This rule identifies RPC Firewall events where a remote RPC client calls the Microsoft RRP registry interface (specific interface UUID) with operation numbers associated with registry modification. Such behavior is important because remote registry changes can be used to alter system settings and potentially enable follow-on actions. It relies on RPC Firewall telemetry (EventLog RPCFW, EventID 3) that records the interface UUID and OpNum for allowed/blocked RPC attempts.
references:
- https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rrp/0fa3191d-bb79-490a-81bd-54c2601b7a78
- https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-RRP.md
- https://github.com/zeronetworks/rpcfirewall
- https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_remote_registry_lateral_movement.yml
author: Sagie Dulce, Dekel Paz, Huntrule Team
date: 2022-01-01
tags:
- attack.lateral-movement
- attack.defense-impairment
- attack.t1112
- attack.persistence
logsource:
product: rpc_firewall
category: application
definition: 'Requirements: install and apply the RPC Firewall to all processes with "audit:true action:block uuid:338cd001-2244-31f1-aaaa-900038001003"'
detection:
selection:
EventLog: RPCFW
EventID: 3
InterfaceUuid: 338cd001-2244-31f1-aaaa-900038001003
OpNum:
- 6
- 7
- 8
- 13
- 18
- 19
- 21
- 22
- 23
- 35
condition: selection
falsepositives:
- Remote administration of registry values
level: high
license: DRL-1.1
related:
- id: 35c55673-84ca-4e99-8d09-e334f3c29539
type: derived
What it detects
This rule identifies RPC Firewall events where a remote RPC client calls the Microsoft RRP registry interface (specific interface UUID) with operation numbers associated with registry modification. Such behavior is important because remote registry changes can be used to alter system settings and potentially enable follow-on actions. It relies on RPC Firewall telemetry (EventLog RPCFW, EventID 3) that records the interface UUID and OpNum for allowed/blocked RPC attempts.
Known false positives
- Remote administration of registry values
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.