Suspicious Persistence Through New SIP Provider (via registry_set)
This rule detects when an adversary register a new SIP provider for persistence and defense evasion
SigmamediumWindowsv1
sigma
suspicious-persistence-through-new-sip-provider-via-registry-set
title: Suspicious Persistence Through New SIP Provider (via registry_set)
id: 69d85308-be89-51ad-85ac-b0dd965a1847
status: stable
description: This rule detects when an adversary register a new SIP provider for persistence and defense evasion
references:
- https://attack.mitre.org/techniques/T1553/003/
- https://persistence-info.github.io/Data/codesigning.html
- https://github.com/gtworek/PSBits/tree/master/SIP
- https://specterops.io/assets/resources/SpecterOps_Subverting_Trust_in_Windows.pdf
author: Huntrule Team
date: 2026-07-09
tags:
- attack.persistence
- attack.defense-impairment
- attack.t1553.003
logsource:
category: registry_set
product: windows
detection:
selection_root:
TargetObject|contains:
- '\SOFTWARE\Microsoft\Cryptography\Providers\'
- '\SOFTWARE\Microsoft\Cryptography\OID\EncodingType'
- '\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\'
- '\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType'
selection_dll:
TargetObject|contains:
- '\Dll'
- '\$DLL'
filter:
Details:
- WINTRUST.DLL
- mso.dll
filter_poqexec:
Image: 'C:\Windows\System32\poqexec.exe'
TargetObject|contains: '\CryptSIPDll'
Details: 'C:\Windows\System32\PsfSip.dll'
condition: all of selection_* and not 1 of filter*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.