Windows Registry EventLog ChannelAccess SDDL Tampering Detection

Detects registry changes to Windows Event Log ChannelAccess SDDL, which can limit event log visibility or control.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
X__Junior (SigmaHQ), DRL 1.1
Published
2025-01-16
Updated
2026-07-30

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies registry modifications to Windows Event Log channel access settings by matching changes to the ChannelAccess values containing Security Descriptor Definition Language (SDDL) patterns. Attackers can use this to restrict who can view or manage specific event log channels, supporting defense evasion by impairing monitoring and forensic visibility. The detection relies on registry_set telemetry that records the TargetObject path and the modified Details content, with exclusions for benign installer/service activity from TrustedInstaller and TiWorker processes.

Related detections9 linkedT1547.001 — drag to rearrange
Suspicious NTUSER.MAN Mandatory Profile File Created for Logon Persistence (via file_event)
Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell
Malicious Enabling of Restricted Admin Mode via Registry by UAT-8837
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Suspicious Autorun Registry Persistence via sausageLoop Run Key
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious BabyLockerKZ Run Key Persistence
Suspicious Run Key Persistence Pointing To User-Writable Path
Malicious Ctrlpanel Run Key Autostart Persistence (via registry_set)
Windows Registry EventLog ChannelAccess SDDL Tampering Detection
Pivot detection · T1547.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.