Windows RPC Firewall Registry Modification Calls via MS-RRP OpNums
Alerts on RPC Firewall registry-interface RPC calls (EventID 3) with OpNums tied to remote registry modification.
- Product
- rpc_firewall
- Category
- application
- Author
- Sagie Dulce, Dekel Paz (SigmaHQ), DRL 1.1
- Published
- 2022-01-01
- Updated
- 2026-07-31
ATT&CK techniques
Persistence → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags RPC Firewall EventLog entries (RPCFW) with InterfaceUuid 338cd001-2244-31f1-aaaa-900038001003 and OpNums 6, 7, 8, 13, 18, 19, 21, 22, 23, and 35. These calls indicate attempts to modify registry state over remote RPC, which can enable persistence or subsequent code execution. It relies on RPC Firewall telemetry capturing the matching InterfaceUuid, operation numbers, and EventID.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rrp/0fa3191d-bb79-490a-81bd-54c2601b7a78
- github.comhttps://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-RRP.md
- github.comhttps://github.com/zeronetworks/rpcfirewall
- zeronetworks.comhttps://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_remote_registry_lateral_movement.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows RPC Firewall Registry Modification Calls via MS-RRP OpNums
id: 8f70e8bc-2aa3-4882-96ff-611def2df62b
status: test
description: This rule flags RPC Firewall EventLog entries (RPCFW) with InterfaceUuid 338cd001-2244-31f1-aaaa-900038001003 and OpNums 6, 7, 8, 13, 18, 19, 21, 22, 23, and 35. These calls indicate attempts to modify registry state over remote RPC, which can enable persistence or subsequent code execution. It relies on RPC Firewall telemetry capturing the matching InterfaceUuid, operation numbers, and EventID.
references:
- https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rrp/0fa3191d-bb79-490a-81bd-54c2601b7a78
- https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-RRP.md
- https://github.com/zeronetworks/rpcfirewall
- https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_remote_registry_lateral_movement.yml
author: Sagie Dulce, Dekel Paz, Huntrule Team
date: 2022-01-01
tags:
- attack.lateral-movement
- attack.defense-impairment
- attack.t1112
- attack.persistence
logsource:
product: rpc_firewall
category: application
definition: 'Requirements: install and apply the RPC Firewall to all processes with "audit:true action:block uuid:338cd001-2244-31f1-aaaa-900038001003"'
detection:
selection:
EventLog: RPCFW
EventID: 3
InterfaceUuid: 338cd001-2244-31f1-aaaa-900038001003
OpNum:
- 6
- 7
- 8
- 13
- 18
- 19
- 21
- 22
- 23
- 35
condition: selection
falsepositives:
- Remote administration of registry values
level: high
license: DRL-1.1
related:
- id: 35c55673-84ca-4e99-8d09-e334f3c29539
type: derived