Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior

Alerts on Windows process activity referencing specific system/IME WimBoot files and registry 'reg add' changes targeting HKLM CLSID inprocserver32.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
MSTIC, FPT.EagleEye (SigmaHQ), DRL 1.1
Published
2021-06-15
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies suspicious Windows process creation and registry modification behavior associated with an actor tracked by Microsoft as SOURGUM. It matches processes that reference specific Windows system files or WimBoot configuration paths and also looks for reg.exe usage combined with targeted registry key patterns under HKEY_LOCAL_MACHINE. Such activity can indicate attempts to persist access or escalate privileges by altering in-process server registrations.

Related detections9 linkedT1546.015 — drag to rearrange
Suspicious COM Hijack of ClickOnce Deployment Service CLSID (via registry_set)
Suspicious COM Hijack Via InprocServer32 Modification
Malicious COM Hijacking via TinyTurla CLSID InprocServer32 (via registry_set)
Suspicious dllhost.exe Spawned with CLSID and Anomalous Parent (via process_creation)
Suspicious COM Handler Hijack of MsCtfMonitor CLSID via CharmingCypress
AdminSDHolder Permissions Changed for Persistence (via security)
Malicious COM Hijack of PSFactoryBuffer InprocServer32
Malicious APT-C-60 COM Hijack via SpyGlace CLSID InProcServer32 (via registry_set)
Malicious COM Hijack via CLSID InProcServer32 Registry Modification (via registry_set)
Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior
Pivot detection · T1546.015 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.