Suspicious File Association Shell Command Handler Hijack via Registry

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-22
Updated
2026-09-22

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects modification of a shell open command handler under the user Classes hive, a file-association hijack SolarMarker uses to trigger its payload when a document type is opened. Redirecting the open command executes attacker code transparently. Detecting the change exposes execution-hijack persistence.

Related detections5 linkedT1546.001 — drag to rearrange
TinyLoader Persistence via txtfile Shell Open Command Hijack (via registry_set)
Windows Registry: Alert on Changes to \shell\open\command Targeting Common Malware Paths
Windows: assoc.exe Changes File Extension Handler to exefile
Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Windows Process: File Association Changes via assoc Command
Suspicious File Association Shell Command Handler Hijack via Registry
Pivot detection · T1546.001 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.