Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\Domains

Flags Windows registry changes to IE ZoneMap domain entries that alter security zone assignments for targeted domains.

FreeUnreviewedSigmamediumv1
title: "Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\\Domains"
id: 9b1d83d2-d8e4-460b-a449-ca7a8d9ed2ef
related:
  - id: d88d0ab2-e696-4d40-a2ed-9790064e66b3
    type: derived
  - id: 45e112d0-7759-4c2a-aa36-9f8fb79d3393
    type: derived
status: test
description: This rule identifies modifications to Internet Explorer security zone mappings by targeting registry keys under ZoneMap\Domains. Changing these zone assignments can enable attackers to influence how domains are treated by the browser, potentially reducing security protections for specific sites. It relies on Windows registry set telemetry capturing writes to Internet Settings ZoneMap Domains entries and applies a filter to exclude specific expected values.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-4---add-domain-to-trusted-sites-zone
  - https://learn.microsoft.com/en-us/troubleshoot/developer/browsers/security-privacy/ie-security-zones-registry-entries
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_change_security_zones.yml
author: frack113, Huntrule Team
date: 2022-01-22
modified: 2023-08-17
tags:
  - attack.persistence
  - attack.t1137
logsource:
  category: registry_set
  product: windows
detection:
  selection_domains:
    TargetObject|contains: \SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
  filter:
    Details:
      - DWORD (0x00000000)
      - DWORD (0x00000001)
      - (Empty)
  condition: selection_domains and not filter
falsepositives:
  - Administrative scripts
level: medium
regression_tests_path: regression_data/rules/windows/registry/registry_set/registry_set_change_security_zones/info.yml
simulation:
  - type: atomic-red-team
    name: Add Domain to Trusted Sites Zone
    technique: T1112
    atomic_guid: cf447677-5a4e-4937-a82c-e47d254afd57
license: DRL-1.1

What it detects

This rule identifies modifications to Internet Explorer security zone mappings by targeting registry keys under ZoneMap\Domains. Changing these zone assignments can enable attackers to influence how domains are treated by the browser, potentially reducing security protections for specific sites. It relies on Windows registry set telemetry capturing writes to Internet Settings ZoneMap Domains entries and applies a filter to exclude specific expected values.

Known false positives

  • Administrative scripts

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.