Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\Domains
Flags Windows registry changes to IE ZoneMap domain entries that alter security zone assignments for targeted domains.
- Product
- windows
- Category
- registry_set
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2022-01-22
- Updated
- 2026-07-30
ATT&CK techniques
PersistenceRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies modifications to Internet Explorer security zone mappings by targeting registry keys under ZoneMap\Domains. Changing these zone assignments can enable attackers to influence how domains are treated by the browser, potentially reducing security protections for specific sites. It relies on Windows registry set telemetry capturing writes to Internet Settings ZoneMap Domains entries and applies a filter to exclude specific expected values.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-4---add-domain-to-trusted-sites-zone
- learn.microsoft.comhttps://learn.microsoft.com/en-us/troubleshoot/developer/browsers/security-privacy/ie-security-zones-registry-entries
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_change_security_zones.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\\Domains"
id: 9b1d83d2-d8e4-460b-a449-ca7a8d9ed2ef
related:
- id: d88d0ab2-e696-4d40-a2ed-9790064e66b3
type: derived
- id: 45e112d0-7759-4c2a-aa36-9f8fb79d3393
type: derived
status: test
description: This rule identifies modifications to Internet Explorer security zone mappings by targeting registry keys under ZoneMap\Domains. Changing these zone assignments can enable attackers to influence how domains are treated by the browser, potentially reducing security protections for specific sites. It relies on Windows registry set telemetry capturing writes to Internet Settings ZoneMap Domains entries and applies a filter to exclude specific expected values.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-4---add-domain-to-trusted-sites-zone
- https://learn.microsoft.com/en-us/troubleshoot/developer/browsers/security-privacy/ie-security-zones-registry-entries
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_change_security_zones.yml
author: frack113, Huntrule Team
date: 2022-01-22
modified: 2023-08-17
tags:
- attack.persistence
- attack.t1137
logsource:
category: registry_set
product: windows
detection:
selection_domains:
TargetObject|contains: \SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
filter:
Details:
- DWORD (0x00000000)
- DWORD (0x00000001)
- (Empty)
condition: selection_domains and not filter
falsepositives:
- Administrative scripts
level: medium
regression_tests_path: regression_data/rules/windows/registry/registry_set/registry_set_change_security_zones/info.yml
simulation:
- type: atomic-red-team
name: Add Domain to Trusted Sites Zone
technique: T1112
atomic_guid: cf447677-5a4e-4937-a82c-e47d254afd57
license: DRL-1.1