Windows Registry and PowerShell Modification of ms-settings Protocol Handler

Flags reg.exe or PowerShell registry edits that alter the ms-settings protocol handler open command path.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113, Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-12-20
Updated
2026-07-30

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule identifies changes to the ms-settings protocol handler command path when registry modifications are performed via reg.exe or through PowerShell. Attackers may use this to redirect protocol execution to attacker-controlled commands, enabling persistence or privilege impact. The detection relies on process creation telemetry that captures reg.exe or PowerShell command-line activity containing specific protocol handler registry key paths and property modification commands.

Related detections9 linkedT1112 — drag to rearrange
Suspicious Remote UAC Restriction Disabled via LocalAccountTokenFilterPolicy (via process_creation)
Suspicious LocalAccountTokenFilterPolicy Registry Modification
Windows Registry: Alert on Changes to \shell\open\command Targeting Common Malware Paths
Malicious Enabling of Restricted Admin Mode via Registry by UAT-8837
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious FodHelper UAC Bypass via ms-settings Shell Command Hijack (via registry_set)
Suspicious Loopback Proxy Server Configured via Registry (via registry_set)
Malicious WDigest Credential Caching Enabled via Registry (via registry_set)
Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.