Windows Registry Autostart Script Keys Modification via System Scripts Policies
Detects Registry writes to System Scripts policy ASEP subkeys for Startup/Shutdown/Logon/Logoff on Windows.
FreeUnreviewedSigmamediumv1
windows-registry-autostart-script-keys-modification-via-system-scripts-policies-e7a2fd40
title: Windows Registry Autostart Script Keys Modification via System Scripts Policies
id: 1c5cb5a2-ae16-4a34-bf08-c897583f9561
related:
- id: 17f878b8-9968-4578-b814-c4217fc5768c
type: obsolete
- id: e7a2fd40-3ae1-4a85-bf80-15cf624fb1b1
type: derived
status: test
description: This rule flags changes to Windows Registry autostart extensibility points (ASEPs) under the System Scripts policy path, specifically the Startup, Shutdown, Logon, and Logoff subkeys. Attackers can use these registry-backed script locations to establish persistence that runs during user session or system state transitions. The detection relies on registry set telemetry capturing updates to TargetObject paths and matches those containing the specified policy and script key segments.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
- https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_system_scripts.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.001
logsource:
category: registry_set
product: windows
detection:
scripts_base:
TargetObject|contains: \Software\Policies\Microsoft\Windows\System\Scripts
scripts:
TargetObject|contains:
- \Startup
- \Shutdown
- \Logon
- \Logoff
filter:
Details: (Empty)
condition: scripts_base and scripts and not filter
falsepositives:
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1
What it detects
This rule flags changes to Windows Registry autostart extensibility points (ASEPs) under the System Scripts policy path, specifically the Startup, Shutdown, Logon, and Logoff subkeys. Attackers can use these registry-backed script locations to establish persistence that runs during user session or system state transitions. The detection relies on registry set telemetry capturing updates to TargetObject paths and matches those containing the specified policy and script key segments.
Known false positives
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.