Windows Registry Key Abuse via Provisioning Commands for Proxy Binary Execution
Flags registry modifications to the Provisioning Commands key path that may enable indirect execution via Provlaunch.exe.
- Product
- windows
- Category
- registry_set
- Author
- Swachchhanda Shrawan Poudel (SigmaHQ), DRL 1.1
- Published
- 2023-08-02
- Updated
- 2026-07-30
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags registry activity involving the Provisioning Commands path under \\SOFTWARE\\Microsoft\\Provisioning\\Commands\\. Attackers can misuse this area to redirect execution through a proxy-style binary such as Provlaunch.exe, helping them run code indirectly while blending into legitimate provisioning mechanisms. The detection relies on registry-set telemetry that includes the TargetObject field containing the monitored registry path.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry Key Abuse via Provisioning Commands for Proxy Binary Execution
id: 9e2ab528-2f11-4160-bb33-a4414cb05403
related:
- id: 7f5d1c9a-3e83-48df-95a7-2b98aae6c13c
type: similar
- id: f9999590-1f94-4a34-a91e-951e47bedefd
type: similar
- id: 2a4b3e61-9d22-4e4a-b60f-6e8f0cde6f25
type: similar
- id: 7021255e-5db3-4946-a8b9-0ba7a4644a69
type: derived
status: test
description: This rule flags registry activity involving the Provisioning Commands path under \\SOFTWARE\\Microsoft\\Provisioning\\Commands\\. Attackers can misuse this area to redirect execution through a proxy-style binary such as Provlaunch.exe, helping them run code indirectly while blending into legitimate provisioning mechanisms. The detection relies on registry-set telemetry that includes the TargetObject field containing the monitored registry path.
references:
- https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/
- https://twitter.com/0gtweet/status/1674399582162153472
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_provisioning_command_abuse.yml
author: Swachchhanda Shrawan Poudel, Huntrule Team
date: 2023-08-02
modified: 2023-08-17
tags:
- attack.stealth
- attack.t1218
logsource:
category: registry_set
product: windows
definition: 'Requirements: The registry key "\SOFTWARE\Microsoft\Provisioning\Commands\" and its subkey must be monitored'
detection:
selection:
TargetObject|contains: \SOFTWARE\Microsoft\Provisioning\Commands\
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1