Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior
Alerts on Windows process activity referencing specific system/IME WimBoot files and registry 'reg add' changes targeting HKLM CLSID inprocserver32.
- Product
- windows
- Category
- process_creation
- Author
- MSTIC, FPT.EagleEye (SigmaHQ), DRL 1.1
- Published
- 2021-06-15
- Updated
- 2026-07-31
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies suspicious Windows process creation and registry modification behavior associated with an actor tracked by Microsoft as SOURGUM. It matches processes that reference specific Windows system files or WimBoot configuration paths and also looks for reg.exe usage combined with targeted registry key patterns under HKEY_LOCAL_MACHINE. Such activity can indicate attempts to persist access or escalate privileges by altering in-process server registrations.
Reporting behind it
- virustotal.comhttps://www.virustotal.com/gui/file/c299063e3eae8ddc15839767e83b9808fd43418dc5a1af7e4f44b97ba53fbd3d/detection
- github.comhttps://github.com/Azure/Azure-Sentinel/blob/43e9be273dca321295190bfc4902858e009d4a35/Detections/MultipleDataSources/SOURGUM_IOC.yaml
- microsoft.comhttps://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/SOURGUM/proc_creation_win_apt_sourgrum.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior
id: 19be21a4-604b-4571-b01a-816e219d7604
status: test
description: This rule identifies suspicious Windows process creation and registry modification behavior associated with an actor tracked by Microsoft as SOURGUM. It matches processes that reference specific Windows system files or WimBoot configuration paths and also looks for reg.exe usage combined with targeted registry key patterns under HKEY_LOCAL_MACHINE. Such activity can indicate attempts to persist access or escalate privileges by altering in-process server registrations.
references:
- https://www.virustotal.com/gui/file/c299063e3eae8ddc15839767e83b9808fd43418dc5a1af7e4f44b97ba53fbd3d/detection
- https://github.com/Azure/Azure-Sentinel/blob/43e9be273dca321295190bfc4902858e009d4a35/Detections/MultipleDataSources/SOURGUM_IOC.yaml
- https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/SOURGUM/proc_creation_win_apt_sourgrum.yml
author: MSTIC, FPT.EagleEye, Huntrule Team
date: 2021-06-15
modified: 2022-10-09
tags:
- attack.t1546
- attack.t1546.015
- attack.persistence
- attack.privilege-escalation
- detection.emerging-threats
logsource:
product: windows
category: process_creation
detection:
selection:
Image|contains:
- windows\system32\Physmem.sys
- Windows\system32\ime\SHARED\WimBootConfigurations.ini
- Windows\system32\ime\IMEJP\WimBootConfigurations.ini
- Windows\system32\ime\IMETC\WimBootConfigurations.ini
registry_image:
Image|contains:
- windows\system32\filepath2
- windows\system32\ime
CommandLine|contains: reg add
registry_key:
CommandLine|contains:
- HKEY_LOCAL_MACHINE\software\classes\clsid\{7c857801-7381-11cf-884d-00aa004b2e24}\inprocserver32
- HKEY_LOCAL_MACHINE\software\classes\clsid\{cf4cc405-e2c5-4ddd-b3ce-5e7582d8c9fa}\inprocserver32
condition: selection or all of registry_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 7ba08e95-1e0b-40cd-9db5-b980555e42fd
type: derived