Windows Registry App Paths Default Property Change Using Suspicious Values

Alerts on Windows App Paths registry edits to (Default)/Path with suspicious binaries, scripts, or temp/public locations.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-10
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags registry changes where the target path is under \Software\Microsoft\Windows\CurrentVersion\App Paths and the modified value name ends with (Default) or Path. It further narrows matches to edits where the Details field contains suspicious path fragments (for example, public user locations and temp directories) or script/loader-related strings such as iex, Invoke-, rundll32, regsvr32, mshta, cscript, wscript, .bat, .hta, .dll, and .ps1. Attackers may use App Paths to influence how applications resolve executable paths and potentially establish persistence-like behavior. Telemetry relies on registry set events capturing TargetObject and the associated Details for the updated value.

Related detections5 linkedT1546.012 — drag to rearrange
Suspicious Image File Execution Options Debugger Hijack (via registry_set)
Malicious IFEO Debugger Hijack of vds.exe by FishMonger
Suspicious Image File Execution Options Debugger Hijack by Miner Campaign
Suspicious Command Processor AutoRun Persistence via Registry Set
Windows Registry Persistence via Image File Execution Options GlobalFlag and SilentProcessExit
Windows Registry App Paths Default Property Change Using Suspicious Values
Pivot detection · T1546.012 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.