Windows Command Execution via Run Dialog (RunMRU) Registry Entries
Flags suspicious Run dialog command entries by matching RunMRU registry key updates on Windows.
FreeReviewedSigma · Low · v5
- Product
- windows
- Category
- registry_set
- Author
- Ahmed Farouk, Nasreddine Bencherchali (SigmaHQ), DRL 1.1
- Published
- 2024-11-01
- Updated
- 2026-07-31
What it detects
This rule identifies potential command execution attempts associated with the Windows Run dialog by matching registry writes under the RunMRU key. Attackers can abuse RunMRU behavior to capture or stage commands and potentially deceive users into running malicious input. The detection relies on Windows registry set telemetry that records TargetObject paths and Details content, including optional indicators such as ping and common command targets.
Reporting behind it
- forensafe.comhttps://www.forensafe.com/blogs/runmrukey.html
- medium.comhttps://medium.com/@shaherzakaria8/downloading-trojan-lumma-infostealer-through-capatcha-1f25255a0e71
- redcanary.comhttps://redcanary.com/blog/threat-intelligence/intelligence-insights-october-2024/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/registry/registry_set/registry_set_runmru_command_execution.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-detect-run-dialog-command-history-in-runmru-registry-f9d091f6
title: Windows Command Execution via Run Dialog (RunMRU) Registry Entries
id: 14e94130-a19c-420f-ae2f-1f8aaa78aa7c
related:
- id: a7df0e9e-91a5-459a-a003-4cde67c2ff5d
type: derived
- id: f9d091f6-f1c7-4873-a24f-050b4a02b4dd
type: derived
status: test
description: This rule identifies potential command execution attempts associated with the Windows Run dialog by matching registry writes under the RunMRU key. Attackers can abuse RunMRU behavior to capture or stage commands and potentially deceive users into running malicious input. The detection relies on Windows registry set telemetry that records TargetObject paths and Details content, including optional indicators such as ping and common command targets.
references:
- https://www.forensafe.com/blogs/runmrukey.html
- https://medium.com/@shaherzakaria8/downloading-trojan-lumma-infostealer-through-capatcha-1f25255a0e71
- https://redcanary.com/blog/threat-intelligence/intelligence-insights-october-2024/
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/registry/registry_set/registry_set_runmru_command_execution.yml
author: Ahmed Farouk, Nasreddine Bencherchali, Huntrule Team
date: 2024-11-01
tags:
- detection.threat-hunting
- attack.execution
logsource:
product: windows
category: registry_set
detection:
selection:
TargetObject|contains: \Microsoft\Windows\CurrentVersion\Explorer\RunMRU
filter_main_mrulist:
TargetObject|endswith: \MRUList
filter_optional_ping:
Details|contains: ping
filter_optional_generic:
Details:
- "%appdata%\\1"
- "%localappdata%\\1"
- "%public%\\1"
- "%temp%\\1"
- calc\1
- dxdiag\1
- explorer\1
- gpedit.msc\1
- mmc\1
- notepad\1
- regedit\1
- services.msc\1
- winver\1
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Likely
level: low
license: DRL-1.1