Suspicious VBScript Payload Stored in CurrentVersion Registry Value (via registry_set)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects registry values written under HKCU or HKLM CurrentVersion that contain VBScript execution keywords such as Execute, vbscript or Shell.Application. Actors including Nobelium stash script payloads in non-Run CurrentVersion values to hide fileless persistence outside the commonly scrutinized Run subkeys.

Related detections9 linkedT1059.005 — drag to rearrange
PowerShell VBScript RegWrite Registry Modification Attempts
VBScript Registry Write Attempt via Wscript.shell RegWrite on Windows
Suspicious VBScript Code Stored in CurrentVersion Registry Value
Suspicious Remote Desktop Enablement via Registry By Ransomware
Suspicious UAC Bypass via control.exe App Paths or Shell Open Command Hijack
Suspicious rundll32 or mshta Proxy Execution of VBScript
Suspicious Office Application Spawning Script Interpreter
Malicious rundll32 vbscript mshtml RunHTMLApplication Execution
Suspicious Script Host Spawned by cmd for DarkGate Execution
Suspicious VBScript Payload Stored in CurrentVersion Registry Value (via registry_set)
Pivot detection · T1059.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.