Windows Registry Persistence via UMe/UT Run Keys

Alerts on Windows registry changes to UMe/UT run key subpaths associated with persistence.

FreeReviewedSigma · Critical · v5
Product
windows
Category
registry_event
Author
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community (SigmaHQ), DRL 1.1
Published
2018-03-23
Updated
2026-07-31

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. Exfiltration

  10. Impact

What it detects

This rule identifies Windows registry writes targeting persistence-related keys under the Microsoft\Windows\CurrentVersion path, specifically ending with UMe and UT. Such persistence can allow an attacker to re-establish execution after reboot by placing entries in well-known startup locations. It relies on registry event telemetry that includes the TargetObject value for the write operation.

Related detections9 linkedT1112 — drag to rearrange
Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
Malicious Impacket SMBexec Service Registration - Native (via security)
Suspicious Hidden Scheduled Task via TaskCache Security Descriptor Manipulation
Suspicious Windows Service Trigger Configuration via Registry Modification
Suspicious Service Persistence Masquerading as DevQueryBrokerService
Windows Registry Persistence via UMe/UT Run Keys
Pivot detection · T1112 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.