Windows Registry CurrentControlSet Control Autorun/ASEP Key Modification
Alerts on Registry changes to Windows ASEP-related keys under CurrentControlSet\Control that can enable persistence.
FreeUnreviewedSigmamediumv1
windows-registry-currentcontrolset-control-autorun-asep-key-modification-f674e36a
title: Windows Registry CurrentControlSet Control Autorun/ASEP Key Modification
id: 77ff894d-b865-4ded-8dfa-9b7a2f770d44
related:
- id: 17f878b8-9968-4578-b814-c4217fc5768c
type: obsolete
- id: f674e36a-4b91-431e-8aef-f8a96c2aca35
type: derived
status: test
description: This rule flags registry modifications under the CurrentControlSet Control path where specific autostart extensibility point (ASEP) subkeys are targeted. Attackers commonly use these locations to establish persistence by configuring programs to start automatically or by altering related startup/provider behaviors. The detection relies on registry_set telemetry that captures the TargetObject path and associated Details/Image/User fields to suppress known benign cases.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
- https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_currentcontrolset.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.001
logsource:
category: registry_set
product: windows
detection:
system_control_base:
TargetObject|contains: \SYSTEM\CurrentControlSet\Control
system_control_keys:
TargetObject|contains:
- \Terminal Server\WinStations\RDP-Tcp\InitialProgram
- \Terminal Server\Wds\rdpwd\StartupPrograms
- \SecurityProviders\SecurityProviders
- \SafeBoot\AlternateShell
- \Print\Providers
- \Print\Monitors
- \NetworkProvider\Order
- \Lsa\Notification Packages
- \Lsa\Authentication Packages
- \BootVerificationProgram\ImagePath
filter_empty:
Details: (Empty)
filter_cutepdf:
Image: C:\Windows\System32\spoolsv.exe
TargetObject|contains: \Print\Monitors\CutePDF Writer Monitor
Details:
- cpwmon64_v40.dll
- CutePDF Writer
filter_onenote:
Image: C:\Windows\System32\spoolsv.exe
TargetObject|contains: Print\Monitors\Appmon\Ports\Microsoft.Office.OneNote_
User|contains:
- AUTHORI
- AUTORI
filter_poqexec:
Image: C:\Windows\System32\poqexec.exe
TargetObject|endswith: \NetworkProvider\Order\ProviderOrder
filter_realvnc:
Image: C:\Windows\System32\spoolsv.exe
TargetObject|endswith: \Print\Monitors\MONVNC\Driver
Details: VNCpm.dll
condition: all of system_control_* and not 1 of filter_*
falsepositives:
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1
What it detects
This rule flags registry modifications under the CurrentControlSet Control path where specific autostart extensibility point (ASEP) subkeys are targeted. Attackers commonly use these locations to establish persistence by configuring programs to start automatically or by altering related startup/provider behaviors. The detection relies on registry_set telemetry that captures the TargetObject path and associated Details/Image/User fields to suppress known benign cases.
Known false positives
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.