Suspicious SOCKS Proxy Autorun Registry Persistence via Registry Set

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Persistence → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule detects a Run key persistence entry whose value references a SOCKS5 proxy component or the PerfLogs staging path. SystemBC establishes a SOCKS5 proxy for command-and-control and anchors it via an autorun registry value, combining persistence with proxy-based C2 tunneling.

Related detections9 linkedT1547.001 — drag to rearrange
Malicious Head Mare Run Key Persistence Masquerading as MicrosoftUpdate
Malicious Coyote Persistence via UserInitMprLogonScript Environment Value (via registry_set)
Suspicious Browser Launched With Injected Proxy Server Argument
Malicious Port Forwarding via QSC pf Tool listen conn Syntax
Suspicious ngrok Tunnel Setup via Authtoken or Service Install (via process_creation)
Malicious SSH Reverse Tunnel with Hidden Key Path (via process_creation)
Suspicious Python Script Persistence in User Startup Folder
Suspicious HealthApp Batch File Persistence in Start Menu Startup Folder
Suspicious FatalRAT Run Key Persistence to ProgramData Loader (via registry_set)
Suspicious SOCKS Proxy Autorun Registry Persistence via Registry Set
Pivot detection · T1547.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.