Windows Registry Autostart Script Keys Modification via System Scripts Policies
Detects Registry writes to System Scripts policy ASEP subkeys for Startup/Shutdown/Logon/Logoff on Windows.
- Product
- windows
- Category
- registry_set
- Author
- Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split) (SigmaHQ), DRL 1.1
- Published
- 2019-10-25
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags changes to Windows Registry autostart extensibility points (ASEPs) under the System Scripts policy path, specifically the Startup, Shutdown, Logon, and Logoff subkeys. Attackers can use these registry-backed script locations to establish persistence that runs during user session or system state transitions. The detection relies on registry set telemetry capturing updates to TargetObject paths and matches those containing the specified policy and script key segments.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
- learn.microsoft.comhttps://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- gist.github.comhttps://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_system_scripts.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry Autostart Script Keys Modification via System Scripts Policies
id: 1c5cb5a2-ae16-4a34-bf08-c897583f9561
related:
- id: 17f878b8-9968-4578-b814-c4217fc5768c
type: obsolete
- id: e7a2fd40-3ae1-4a85-bf80-15cf624fb1b1
type: derived
status: test
description: This rule flags changes to Windows Registry autostart extensibility points (ASEPs) under the System Scripts policy path, specifically the Startup, Shutdown, Logon, and Logoff subkeys. Attackers can use these registry-backed script locations to establish persistence that runs during user session or system state transitions. The detection relies on registry set telemetry capturing updates to TargetObject paths and matches those containing the specified policy and script key segments.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
- https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_system_scripts.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.001
logsource:
category: registry_set
product: windows
detection:
scripts_base:
TargetObject|contains: \Software\Policies\Microsoft\Windows\System\Scripts
scripts:
TargetObject|contains:
- \Startup
- \Shutdown
- \Logon
- \Logoff
filter:
Details: (Empty)
condition: scripts_base and scripts and not filter
falsepositives:
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1