Windows Registry CurrentControlSet Control Autorun/ASEP Key Modification

Alerts on Registry changes to Windows ASEP-related keys under CurrentControlSet\Control that can enable persistence.

FreeUnreviewedSigmamediumv1
title: Windows Registry CurrentControlSet Control Autorun/ASEP Key Modification
id: 77ff894d-b865-4ded-8dfa-9b7a2f770d44
related:
  - id: 17f878b8-9968-4578-b814-c4217fc5768c
    type: obsolete
  - id: f674e36a-4b91-431e-8aef-f8a96c2aca35
    type: derived
status: test
description: This rule flags registry modifications under the CurrentControlSet Control path where specific autostart extensibility point (ASEP) subkeys are targeted. Attackers commonly use these locations to establish persistence by configuring programs to start automatically or by altering related startup/provider behaviors. The detection relies on registry_set telemetry that captures the TargetObject path and associated Details/Image/User fields to suppress known benign cases.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
  - https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
  - https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_currentcontrolset.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1547.001
logsource:
  category: registry_set
  product: windows
detection:
  system_control_base:
    TargetObject|contains: \SYSTEM\CurrentControlSet\Control
  system_control_keys:
    TargetObject|contains:
      - \Terminal Server\WinStations\RDP-Tcp\InitialProgram
      - \Terminal Server\Wds\rdpwd\StartupPrograms
      - \SecurityProviders\SecurityProviders
      - \SafeBoot\AlternateShell
      - \Print\Providers
      - \Print\Monitors
      - \NetworkProvider\Order
      - \Lsa\Notification Packages
      - \Lsa\Authentication Packages
      - \BootVerificationProgram\ImagePath
  filter_empty:
    Details: (Empty)
  filter_cutepdf:
    Image: C:\Windows\System32\spoolsv.exe
    TargetObject|contains: \Print\Monitors\CutePDF Writer Monitor
    Details:
      - cpwmon64_v40.dll
      - CutePDF Writer
  filter_onenote:
    Image: C:\Windows\System32\spoolsv.exe
    TargetObject|contains: Print\Monitors\Appmon\Ports\Microsoft.Office.OneNote_
    User|contains:
      - AUTHORI
      - AUTORI
  filter_poqexec:
    Image: C:\Windows\System32\poqexec.exe
    TargetObject|endswith: \NetworkProvider\Order\ProviderOrder
  filter_realvnc:
    Image: C:\Windows\System32\spoolsv.exe
    TargetObject|endswith: \Print\Monitors\MONVNC\Driver
    Details: VNCpm.dll
  condition: all of system_control_* and not 1 of filter_*
falsepositives:
  - Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
  - Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1

What it detects

This rule flags registry modifications under the CurrentControlSet Control path where specific autostart extensibility point (ASEP) subkeys are targeted. Attackers commonly use these locations to establish persistence by configuring programs to start automatically or by altering related startup/provider behaviors. The detection relies on registry_set telemetry that captures the TargetObject path and associated Details/Image/User fields to suppress known benign cases.

Known false positives

  • Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
  • Legitimate administrator sets up autorun keys for legitimate reason

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.