Windows Registry: Detect esentutl.exe activity under VSS service keys

Flags registry changes under VSS service keys when initiated by esentutl.exe, consistent with VSS-related abuse.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_event
Author
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) (SigmaHQ), DRL 1.1
Published
2020-10-20
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows registry activity involving the Volume Shadow Copy Service (VSS) service subtree when the initiating process is esentutl.exe. Attackers may use VSS-related functionality to support credential access and other post-compromise objectives, making service initialization and processing relevant. It relies on registry event telemetry that records the TargetObject being modified and the Image path for the process (filtered to exclude Start-related entries).

Related detections9 linkedT1003.002 — drag to rearrange
Credential Dumping via Reg Save of SAM Hive
Malicious Registry Hive Dump via reg save
Suspicious Archiving of Registry Hives via WinRAR (UAT-8099)
Malicious Registry Hive Dump of SAM or SYSTEM via Reg Save (via process_creation)
Malicious Credential Hive Copy from Volume Shadow Copy
Malicious Secretdump Password Dumping via SMB Admin Share (via security)
Malicious Registry Hive Dump of SAM and SYSTEM via Reg Save (via process_creation)
Suspicious SAM Registry Hive Dump to Windows Temp by BianLian
Malicious SAM and SYSTEM Hive Dump via reg save (via process_creation)
Windows Registry: Detect esentutl.exe activity under VSS service keys
Pivot detection · T1003.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.