Windows reg.exe importing .reg files from common user and temp directories
Flags reg.exe importing .reg files when the command line references user or temp directories.
- Product
- windows
- Category
- process_creation
- Author
- frack113, Nasreddine Bencherchali (SigmaHQ), DRL 1.1
- Published
- 2022-08-01
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies process creations where reg.exe is used to import .reg files, with the command line containing an import action and the command referencing common user and temporary paths (e.g., %temp%, %tmp%, %appdata%, AppData Local Temp, Windows Temp, and ProgramData). Such activity matters because importing registry files can change system settings and persistence-relevant configurations. The detection relies on Windows process creation telemetry, including the process image/original filename and the command line content and path strings.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows reg.exe importing .reg files from common user and temp directories
id: e4a38e75-311c-44e1-8463-ad4335993a77
related:
- id: 73bba97f-a82d-42ce-b315-9182e76c57b1
type: derived
- id: 62e0298b-e994-4189-bc87-bc699aa62d97
type: derived
status: test
description: This rule identifies process creations where reg.exe is used to import .reg files, with the command line containing an import action and the command referencing common user and temporary paths (e.g., %temp%, %tmp%, %appdata%, AppData Local Temp, Windows Temp, and ProgramData). Such activity matters because importing registry files can change system settings and persistence-relevant configurations. The detection relies on Windows process creation telemetry, including the process image/original filename and the command line content and path strings.
references:
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/reg-import
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_reg_import_from_suspicious_paths.yml
author: frack113, Nasreddine Bencherchali, Huntrule Team
date: 2022-08-01
modified: 2023-02-05
tags:
- attack.persistence
- attack.defense-impairment
- attack.t1112
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \reg.exe
- OriginalFileName: reg.exe
selection_cli:
CommandLine|contains: " import "
selection_paths:
CommandLine|contains:
- C:\Users\
- "%temp%"
- "%tmp%"
- "%appdata%"
- \AppData\Local\Temp\
- C:\Windows\Temp\
- C:\ProgramData\
condition: all of selection_*
falsepositives:
- Legitimate import of keys
level: medium
license: DRL-1.1