Windows Registry AMSI Provider Persistence via Providers Key

Alerts on registry activity creating/modifying AMSI provider entries under the Microsoft AMSI Providers keys.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-21
Updated
2026-07-30

What it detects

This rule flags registry writes targeting the AMSI providers locations under HKLM, specifically paths containing \SOFTWARE\Microsoft\AMSI\Providers\ and \SOFTWARE\WOW6432Node\Microsoft\AMSI\Providers\, which indicate creation or modification of AMSI provider entries. Adding new AMSI providers can be used to influence how AMSI content is scanned, potentially aiding evasion or persistence. It relies on registry set events that include the TargetObject (registry path) and the Image responsible for the change, with optional exclusions for specific vendor registration tools.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.