Windows Command Execution via Run Dialog (RunMRU) Registry Entries

Flags suspicious Run dialog command entries by matching RunMRU registry key updates on Windows.

FreeReviewedSigma · Low · v5
Product
windows
Category
registry_set
Author
Ahmed Farouk, Nasreddine Bencherchali (SigmaHQ), DRL 1.1
Published
2024-11-01
Updated
2026-07-31

What it detects

This rule identifies potential command execution attempts associated with the Windows Run dialog by matching registry writes under the RunMRU key. Attackers can abuse RunMRU behavior to capture or stage commands and potentially deceive users into running malicious input. The detection relies on Windows registry set telemetry that records TargetObject paths and Details content, including optional indicators such as ping and common command targets.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.