Suspicious HrServ Registry Command Channel under IdentityStore RemoteFile (via registry_set)

PremiumReviewedSigma · High · v1
Category
registry_set
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects writes to the HKLM\SOFTWARE\Microsoft\IdentityStore\RemoteFile registry value. The HrServ web shell abuses this uncommon key as a covert channel to stage and exchange data, so modification of this specific path indicates the implant storing operator content in the registry.

Related detections9 linkedT1112 — drag to rearrange
Malicious Microsoft Defender Disable via Registry by Key Group
Suspicious PowerShell Decoding Base64 Payload Stored in Registry
Suspicious Remote Desktop Enablement via Registry By Ransomware
Suspicious VBScript Payload Stored in CurrentVersion Registry Value (via registry_set)
Suspicious UAC Bypass via control.exe App Paths or Shell Open Command Hijack
Malicious Restricted Admin Mode Enabled for Pass-the-Hash RDP
Malicious Windows Defender Service Disable via Registry
Suspicious RDP Enablement via fDenyTSConnections Registry Modification
LanmanServer MaxMpxCt Registry Modification for Lateral Movement Preparation
Suspicious HrServ Registry Command Channel under IdentityStore RemoteFile (via registry_set)
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.