Suspicious SmartScreen Disable via Registry Modification via registry_set

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects modification of the AppHost registry values that control SmartScreen web content evaluation which attackers disable to suppress reputation-based download warnings. The Arcane stealer turned off EnableWebContentEvaluation and SmartScreenEnabled to let its downloaded tools run without user prompts. Disabling SmartScreen weakens a key browser defense and is rarely legitimate on managed endpoints.

Related detections9 linkedT1685 — drag to rearrange
Malicious Microsoft Defender Disable via Registry by Key Group
Malicious Windows Defender Service Disable via Registry
Malicious Microsoft Defender Tamper via Registry Modification
Malicious Defender Real-Time Monitoring Disable via Registry
Suspicious HrServ Registry Command Channel under IdentityStore RemoteFile (via registry_set)
Suspicious Process Made Critical via RtlSetProcessIsCritical (via ps_script)
Malicious Defender Exclusion Added for User Profile Path
Suspicious Defender Protection Disabled via Set-MpPreference
Suspicious PowerShell Decoding Base64 Payload Stored in Registry
Suspicious SmartScreen Disable via Registry Modification via registry_set
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.