Windows Registry Image File Execution Options Debugger Backdoor (sethc.exe/utilman.exe/osk.exe)

Alerts on registry Debugger hijacks for Windows login/accessibility binaries using Image File Execution Options.

FreeUnreviewedSigmacriticalv1
title: Windows Registry Image File Execution Options Debugger Backdoor (sethc.exe/utilman.exe/osk.exe)
id: da462992-ddbe-4d9e-beee-82cea9320e3e
status: test
description: This rule flags registry entries that set a Debugger value for built-in Windows executables via the Image File Execution Options mechanism. Attackers can abuse this to hijack execution of accessibility and login-screen tools such as sethc.exe, utilman.exe, and others. The detection relies on Windows registry event telemetry for writes or modifications to specific Debugger key paths under CurrentVersion\Image File Execution Options.
references:
  - https://blogs.technet.microsoft.com/jonathantrull/2016/10/03/detecting-sticky-key-backdoors/
  - https://bazaar.abuse.ch/sample/6f3aa9362d72e806490a8abce245331030d1ab5ac77e400dd475748236a6cc81/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_event/registry_event_stickykey_like_backdoor.yml
author: Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, Huntrule Team
date: 2018-03-15
modified: 2022-11-26
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1546.008
  - car.2014-11-003
  - car.2014-11-008
logsource:
  category: registry_event
  product: windows
detection:
  selection_registry:
    TargetObject|endswith:
      - \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe\Debugger
      - \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe\Debugger
      - \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\osk.exe\Debugger
      - \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Magnify.exe\Debugger
      - \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Narrator.exe\Debugger
      - \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DisplaySwitch.exe\Debugger
      - \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atbroker.exe\Debugger
      - \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HelpPane.exe\Debugger
  condition: selection_registry
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: baca5663-583c-45f9-b5dc-ea96a22ce542
    type: derived

What it detects

This rule flags registry entries that set a Debugger value for built-in Windows executables via the Image File Execution Options mechanism. Attackers can abuse this to hijack execution of accessibility and login-screen tools such as sethc.exe, utilman.exe, and others. The detection relies on Windows registry event telemetry for writes or modifications to specific Debugger key paths under CurrentVersion\Image File Execution Options.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.