Windows Registry: Attachment Manager policy tampering via Attachments settings values

Detects registry changes to Windows Attachment Manager policy values that can disable or alter download safety controls.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-01
Updated
2026-07-30

What it detects

This rule flags modifications to Microsoft Windows Attachment Manager policy settings stored under the Attachments registry path. Attackers may tamper with these controls to affect how downloaded files are treated, potentially weakening user safety prompts and security scanning behavior. It relies on registry set telemetry by matching the target registry keys and specific DWORD values indicating HideZoneInfoOnProperties, SaveZoneInformation, and ScanWithAntiVirus state changes.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.