Windows: Registry CreateKey/Rename of HKLM\SYSTEM\CurrentControlSet\Control\MiniNt

Flags registry creation or renaming of the MiniNt key that can impair Windows event logging after reboot.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_event
Author
Ilyas Ochkov, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-25
Updated
2026-07-30
title: "Windows: Registry CreateKey/Rename of HKLM\\SYSTEM\\CurrentControlSet\\Control\\MiniNt"
id: f072b96f-19c3-4328-95c0-55eaae884cb8
status: test
description: This rule identifies attempts to create or rename the registry key HKLM\SYSTEM\CurrentControlSet\Control\MiniNt. Adding this key can disable Windows event logging after a reboot, which matters to attackers seeking defense impairment by reducing available audit telemetry. It relies on registry event telemetry capturing key creation and rename activity, including the target object or the new registry key name.
references:
  - https://twitter.com/0gtweet/status/1182516740955226112
  - https://www.hackingarticles.in/defense-evasion-windows-event-logging-t1562-002/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_event/registry_event_disable_security_events_logging_adding_reg_key_minint.yml
author: Ilyas Ochkov, oscd.community, Huntrule Team
date: 2019-10-25
modified: 2021-11-27
tags:
  - attack.persistence
  - attack.defense-impairment
  - attack.t1685.001
  - attack.t1112
  - car.2022-03-001
logsource:
  category: registry_event
  product: windows
detection:
  selection:
    - TargetObject: HKLM\SYSTEM\CurrentControlSet\Control\MiniNt
      EventType: CreateKey
    - NewName: HKLM\SYSTEM\CurrentControlSet\Control\MiniNt
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 919f2ef0-be2d-4a7a-b635-eb2b41fde044
    type: derived