Suspicious Modification of CloudFiles BlockedApps Policy via registry_set

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects writes to the CloudFiles BlockedApps policy key under the default user hive, abused during MiniPlasma privilege escalation through a registry symlink to Volatile Environment. This key is not a normal target for user or application configuration. Tampering here supports the exploit primitive used to elevate privileges.

Related detections9 linkedT1112 — drag to rearrange
Suspicious Disabling of Malicious Software Removal Tool via registry_set
Suspicious SmartScreen Disable via Registry Modification via registry_set
Suspicious HrServ Registry Command Channel under IdentityStore RemoteFile (via registry_set)
Malicious Microsoft Defender Disable via Registry by Key Group
Suspicious Command Shell Spawned by lmadmin License Manager via process_creation
Suspicious PowerShell Decoding Base64 Payload Stored in Registry
Suspicious Named Pipe TyphoonPWN Local Privilege Escalation Marker (via pipe_created)
Suspicious Dell DBUtilDrv2 Vulnerable Driver Load via driver_load
Suspicious Remote Desktop Enablement via Registry By Ransomware
Suspicious Modification of CloudFiles BlockedApps Policy via registry_set
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.