Windows Registry Add WFP Filter Rules via BFE Parameters Path
Alerts on registry changes adding persistent WFP filters under the BFE policy persistent filter path via svchost.exe.
- Product
- windows
- Category
- registry_set
- Author
- Frack113 (SigmaHQ), DRL 1.1
- Published
- 2025-10-23
- Updated
- 2026-07-30
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags registry set events where the target path contains the Windows Filtering Platform (WFP) persistent filter parameters under \BFE\Parameters\Policy\Persistent\Filter\. Such changes can be used to alter host networking enforcement and may support defense-impairment goals by disrupting visibility from security tooling. It relies on Windows registry modification telemetry, matching both the target object path and the process image executing svchost.exe in 32-bit or 64-bit contexts.
Reporting behind it
- github.comhttps://github.com/netero1010/EDRSilencer/blob/0e73a7037ec65c52894d8208e6f605a7da0a34a6/EDRSilencer.c
- huntress.comhttps://www.huntress.com/blog/silencing-the-edr-silencers
- trendmicro.comhttps://www.trendmicro.com/en_us/research/24/j/edrsilencer-disrupting-endpoint-security-solutions.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_susp_wfp_filter_added.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry Add WFP Filter Rules via BFE Parameters Path
id: 44438914-cfd4-457c-9c77-77bcdab022a5
status: experimental
description: This rule flags registry set events where the target path contains the Windows Filtering Platform (WFP) persistent filter parameters under \BFE\Parameters\Policy\Persistent\Filter\. Such changes can be used to alter host networking enforcement and may support defense-impairment goals by disrupting visibility from security tooling. It relies on Windows registry modification telemetry, matching both the target object path and the process image executing svchost.exe in 32-bit or 64-bit contexts.
references:
- https://github.com/netero1010/EDRSilencer/blob/0e73a7037ec65c52894d8208e6f605a7da0a34a6/EDRSilencer.c
- https://www.huntress.com/blog/silencing-the-edr-silencers
- https://www.trendmicro.com/en_us/research/24/j/edrsilencer-disrupting-endpoint-security-solutions.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_susp_wfp_filter_added.yml
author: Frack113, Huntrule Team
date: 2025-10-23
tags:
- attack.execution
- attack.defense-impairment
- attack.t1685
- attack.t1569.002
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains: \BFE\Parameters\Policy\Persistent\Filter\
filter_main_svchost:
Image:
- C:\Windows\System32\svchost.exe
- C:\Windows\SysWOW64\svchost.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 1f1d8209-636e-4c6c-a137-781cca8b82f9
type: derived