Windows Recall Enabled by Registry: DisableAIDataAnalysis Set to 0 (Windows)
Alerts when Windows Recall is enabled by setting the DisableAIDataAnalysis policy value to 0.
FreeUnreviewedSigmamediumv1
windows-recall-enabled-by-registry-disableaidataanalysis-set-to-0-windows-75180c5f
title: "Windows Recall Enabled by Registry: DisableAIDataAnalysis Set to 0 (Windows)"
id: bd467112-2db2-42f6-8fda-c4402950e142
related:
- id: 5dfc1465-8f65-4fde-8eb5-6194380c6a62
type: similar
- id: 817f252c-5143-4dae-b418-48c3e9f63728
type: similar
- id: 75180c5f-4ea1-461a-a4f6-6e4700c065d4
type: derived
status: test
description: This rule flags registry changes that enable Windows Recall by setting DisableAIDataAnalysis to DWORD 0x00000000 under the WindowsAI policy path. Enabling this feature can support collection and discovery workflows after compromise, making it a useful signal for post-exploitation activity. It relies on telemetry showing registry set operations matching the specific policy key and value type and data.
references:
- https://learn.microsoft.com/en-us/windows/client-management/manage-recall
- https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-windowsai#disableaidataanalysis
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_enable_windows_recall.yml
author: Sajid Nawaz Khan, Huntrule Team
date: 2024-06-02
tags:
- attack.collection
- attack.t1113
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|endswith: \Software\Policies\Microsoft\Windows\WindowsAI\DisableAIDataAnalysis
Details: DWORD (0x00000000)
condition: selection
falsepositives:
- Legitimate use/activation of Windows Recall
level: medium
license: DRL-1.1
What it detects
This rule flags registry changes that enable Windows Recall by setting DisableAIDataAnalysis to DWORD 0x00000000 under the WindowsAI policy path. Enabling this feature can support collection and discovery workflows after compromise, making it a useful signal for post-exploitation activity. It relies on telemetry showing registry set operations matching the specific policy key and value type and data.
Known false positives
- Legitimate use/activation of Windows Recall
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.