RPC Firewall detects remote registry modification via Microsoft RRP interface calls (OpNum 6/7/8/13/18/19/21/22/23/35)

Alerts on RPC Firewall registry-interface RPC calls (EventID 3) with OpNums tied to remote registry modification.

FreeUnreviewedSigmahighv1
title: RPC Firewall detects remote registry modification via Microsoft RRP interface calls (OpNum 6/7/8/13/18/19/21/22/23/35)
id: 8f70e8bc-2aa3-4882-96ff-611def2df62b
status: test
description: This rule identifies RPC Firewall events where a remote RPC client calls the Microsoft RRP registry interface (specific interface UUID) with operation numbers associated with registry modification. Such behavior is important because remote registry changes can be used to alter system settings and potentially enable follow-on actions. It relies on RPC Firewall telemetry (EventLog RPCFW, EventID 3) that records the interface UUID and OpNum for allowed/blocked RPC attempts.
references:
  - https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rrp/0fa3191d-bb79-490a-81bd-54c2601b7a78
  - https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-RRP.md
  - https://github.com/zeronetworks/rpcfirewall
  - https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_remote_registry_lateral_movement.yml
author: Sagie Dulce, Dekel Paz, Huntrule Team
date: 2022-01-01
tags:
  - attack.lateral-movement
  - attack.defense-impairment
  - attack.t1112
  - attack.persistence
logsource:
  product: rpc_firewall
  category: application
  definition: 'Requirements: install and apply the RPC Firewall to all processes with "audit:true action:block uuid:338cd001-2244-31f1-aaaa-900038001003"'
detection:
  selection:
    EventLog: RPCFW
    EventID: 3
    InterfaceUuid: 338cd001-2244-31f1-aaaa-900038001003
    OpNum:
      - 6
      - 7
      - 8
      - 13
      - 18
      - 19
      - 21
      - 22
      - 23
      - 35
  condition: selection
falsepositives:
  - Remote administration of registry values
level: high
license: DRL-1.1
related:
  - id: 35c55673-84ca-4e99-8d09-e334f3c29539
    type: derived

What it detects

This rule identifies RPC Firewall events where a remote RPC client calls the Microsoft RRP registry interface (specific interface UUID) with operation numbers associated with registry modification. Such behavior is important because remote registry changes can be used to alter system settings and potentially enable follow-on actions. It relies on RPC Firewall telemetry (EventLog RPCFW, EventID 3) that records the interface UUID and OpNum for allowed/blocked RPC attempts.

Known false positives

  • Remote administration of registry values

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.