Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\Domains
Flags Windows registry changes to IE ZoneMap domain entries that alter security zone assignments for targeted domains.
FreeUnreviewedSigmamediumv1
windows-registry-ie-zonemap-domain-zone-change-via-zonemap-domains-45e112d0
title: "Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\\Domains"
id: 9b1d83d2-d8e4-460b-a449-ca7a8d9ed2ef
related:
- id: d88d0ab2-e696-4d40-a2ed-9790064e66b3
type: derived
- id: 45e112d0-7759-4c2a-aa36-9f8fb79d3393
type: derived
status: test
description: This rule identifies modifications to Internet Explorer security zone mappings by targeting registry keys under ZoneMap\Domains. Changing these zone assignments can enable attackers to influence how domains are treated by the browser, potentially reducing security protections for specific sites. It relies on Windows registry set telemetry capturing writes to Internet Settings ZoneMap Domains entries and applies a filter to exclude specific expected values.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-4---add-domain-to-trusted-sites-zone
- https://learn.microsoft.com/en-us/troubleshoot/developer/browsers/security-privacy/ie-security-zones-registry-entries
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_change_security_zones.yml
author: frack113, Huntrule Team
date: 2022-01-22
modified: 2023-08-17
tags:
- attack.persistence
- attack.t1137
logsource:
category: registry_set
product: windows
detection:
selection_domains:
TargetObject|contains: \SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
filter:
Details:
- DWORD (0x00000000)
- DWORD (0x00000001)
- (Empty)
condition: selection_domains and not filter
falsepositives:
- Administrative scripts
level: medium
regression_tests_path: regression_data/rules/windows/registry/registry_set/registry_set_change_security_zones/info.yml
simulation:
- type: atomic-red-team
name: Add Domain to Trusted Sites Zone
technique: T1112
atomic_guid: cf447677-5a4e-4937-a82c-e47d254afd57
license: DRL-1.1
What it detects
This rule identifies modifications to Internet Explorer security zone mappings by targeting registry keys under ZoneMap\Domains. Changing these zone assignments can enable attackers to influence how domains are treated by the browser, potentially reducing security protections for specific sites. It relies on Windows registry set telemetry capturing writes to Internet Settings ZoneMap Domains entries and applies a filter to exclude specific expected values.
Known false positives
- Administrative scripts
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.