Suspicious Disabling of Malicious Software Removal Tool via registry_set

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the DontOfferThroughWUAU value being set under the MRT policy key to stop Windows from offering the Malicious Software Removal Tool. The pirated-media miner campaign sets this to weaken host defenses. Suppressing built-in cleanup tooling is a defense-evasion tactic that precedes long-term persistence.

Related detections9 linkedT1112 — drag to rearrange
Suspicious Modification of CloudFiles BlockedApps Policy via registry_set
Suspicious SmartScreen Disable via Registry Modification via registry_set
Suspicious HrServ Registry Command Channel under IdentityStore RemoteFile (via registry_set)
Malicious Microsoft Defender Disable via Registry by Key Group
Suspicious PowerShell Decoding Base64 Payload Stored in Registry
Suspicious Remote Desktop Enablement via Registry By Ransomware
Suspicious VBScript Payload Stored in CurrentVersion Registry Value (via registry_set)
Suspicious UAC Bypass via control.exe App Paths or Shell Open Command Hijack
Malicious Restricted Admin Mode Enabled for Pass-the-Hash RDP
Suspicious Disabling of Malicious Software Removal Tool via registry_set
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.