Windows Command-Line Persistence via TypedPaths Registry Modification

Flags command-line activity referencing the Explorer TypedPaths registry path, which may indicate persistence via registry modification.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-22
Updated
2026-07-30

What it detects

This rule matches process creation events where the command line contains the registry path for Explorer TypedPaths under the CurrentVersion key. Modifying TypedPaths can indicate an attempt to create or alter persistence behavior by changing how Explorer resolves typed path entries. Telemetry relies on Windows process creation logs with access to the full command line string.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.