Windows AppCompatFlags Store New Application Registry Entries
Alerts on new writes to the AppCompat Compatibility Assistant store registry path, indicating first-time application behavior.
FreeUnreviewedSigmainformationalv1
windows-appcompatflags-store-new-application-registry-entries-60936b49
title: Windows AppCompatFlags Store New Application Registry Entries
id: 9b7ffda5-4fb6-4799-93d1-dd5e309a9a61
status: test
description: This rule flags registry set events where the target path includes the AppCompat Compatibility Assistant store directory. It indicates an application write associated with the AppCompatFlags compatibility assistant storage, which can occur when software executes or is first established on an endpoint. The detection relies on Windows registry_set telemetry capturing the TargetObject path.
references:
- https://github.com/OTRF/detection-hackathon-apt29/issues/1
- https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/1.A.1_DFD6A782-9BDB-4550-AB6B-525E825B095E.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_new_application_appcompat.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2020-05-02
modified: 2023-08-17
tags:
- attack.execution
- attack.t1204.002
logsource:
product: windows
category: registry_set
detection:
selection:
TargetObject|contains: \AppCompatFlags\Compatibility Assistant\Store\
condition: selection
falsepositives:
- This rule is to explore new applications on an endpoint. False positives depends on the organization.
- Newly setup system.
- Legitimate installation of new application.
level: informational
license: DRL-1.1
related:
- id: 60936b49-fca0-4f32-993d-7415edcf9a5d
type: derived
What it detects
This rule flags registry set events where the target path includes the AppCompat Compatibility Assistant store directory. It indicates an application write associated with the AppCompatFlags compatibility assistant storage, which can occur when software executes or is first established on an endpoint. The detection relies on Windows registry_set telemetry capturing the TargetObject path.
Known false positives
- This rule is to explore new applications on an endpoint. False positives depends on the organization.
- Newly setup system.
- Legitimate installation of new application.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.