Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
- Product
- windows
- Category
- process_creation
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2026-01-26
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies command-line activity that uses reg.exe (or PowerShell/pwsh) to add or modify registry values related to Hypervisor-protected Code Integrity by targeting DeviceGuard settings and HVCI-specific keys. Tampering with HVCI configuration can enable malicious or otherwise untrusted kernel-mode drivers and can undermine security controls, supporting privilege escalation, persistence, or defense evasion. It relies on process creation telemetry including the originating image, original file name, and the executed command line content matching HVCI/DeviceGuard registry-related operations.
Reporting behind it
- sophos.comhttps://www.sophos.com/en-us/blog/sharpening-the-knife-gold-blades-strategic-evolution
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hvci_registry_tampering.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
id: a0fe4e52-015b-42ba-bf1e-13934a4237d4
related:
- id: 8b7273a4-ba5d-4d8a-b04f-11f2900d043a
type: similar
- id: 6225c53a-a96e-4235-b28f-8d7997cd96eb
type: derived
status: experimental
description: This rule identifies command-line activity that uses reg.exe (or PowerShell/pwsh) to add or modify registry values related to Hypervisor-protected Code Integrity by targeting DeviceGuard settings and HVCI-specific keys. Tampering with HVCI configuration can enable malicious or otherwise untrusted kernel-mode drivers and can undermine security controls, supporting privilege escalation, persistence, or defense evasion. It relies on process creation telemetry including the originating image, original file name, and the executed command line content matching HVCI/DeviceGuard registry-related operations.
references:
- https://www.sophos.com/en-us/blog/sharpening-the-knife-gold-blades-strategic-evolution
- https://learn.microsoft.com/en-us/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hvci_registry_tampering.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-01-26
tags:
- attack.defense-impairment
- attack.t1685
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \powershell.exe
- \pwsh.exe
- \reg.exe
- OriginalFileName:
- PowerShell.EXE
- pwsh.dll
- reg.exe
selection_cli:
CommandLine|contains:
- "add "
- "New-ItemProperty "
- "Set-ItemProperty "
- "si "
selection_cli_base:
CommandLine|contains: \DeviceGuard
selection_cli_key:
CommandLine|contains:
- EnableVirtualizationBasedSecurity
- HypervisorEnforcedCodeIntegrity
condition: all of selection_*
falsepositives:
- Legitimate system administration tasks that require disabling HVCI for troubleshooting purposes when certain drivers or applications are incompatible with it.
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_hvci_registry_tampering/info.yml
simulation:
- type: atomic-red-team
name: Disable Hypervisor-Enforced Code Integrity (HVCI)
technique: T1562.001
atomic_guid: 70bd71e6-eba4-4e00-92f7-617911dbe020
license: DRL-1.1