Windows Registry Modification of Internet Explorer Autostart Extension Keys (ASEP)

Flags Windows registry changes to Internet Explorer ASEP extension/toolbar keys associated with persistence.

FreeUnreviewedSigmamediumv1
title: Windows Registry Modification of Internet Explorer Autostart Extension Keys (ASEP)
id: a09ccc8c-096b-46af-a8c8-8a3e6ed2d297
related:
  - id: 17f878b8-9968-4578-b814-c4217fc5768c
    type: obsolete
  - id: a80f662f-022f-4429-9b8c-b1a41aaa6688
    type: derived
status: test
description: This rule identifies registry changes targeting Internet Explorer AutoStart Extensibility Point (ASEP) locations under the 32-bit and 64-bit Internet Explorer keys. It focuses on extension and toolbar-related subkeys that attackers may use to persist or execute code within Internet Explorer. The detection relies on registry set events and matches the TargetObject path components, while excluding specific known extension and toolbar layouts that commonly cause benign results. It also filters out empty Details entries to reduce noise.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
  - https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
  - https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_internet_explorer.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1547.001
logsource:
  category: registry_set
  product: windows
detection:
  ie:
    TargetObject|contains:
      - \Software\Wow6432Node\Microsoft\Internet Explorer
      - \Software\Microsoft\Internet Explorer
  ie_details:
    TargetObject|contains:
      - \Toolbar
      - \Extensions
      - \Explorer Bars
  filter_empty:
    Details: (Empty)
  filter_extensions:
    TargetObject|contains:
      - \Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}
      - \Extensions\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}
      - \Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
      - \Extensions\{A95fe080-8f5d-11d2-a20b-00aa003c157a}
  filter_toolbar:
    TargetObject|endswith:
      - \Toolbar\ShellBrowser\ITBar7Layout
      - \Toolbar\ShowDiscussionButton
      - \Toolbar\Locked
  condition: ie and ie_details and not 1 of filter_*
falsepositives:
  - Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
  - Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1

What it detects

This rule identifies registry changes targeting Internet Explorer AutoStart Extensibility Point (ASEP) locations under the 32-bit and 64-bit Internet Explorer keys. It focuses on extension and toolbar-related subkeys that attackers may use to persist or execute code within Internet Explorer. The detection relies on registry set events and matches the TargetObject path components, while excluding specific known extension and toolbar layouts that commonly cause benign results. It also filters out empty Details entries to reduce noise.

Known false positives

  • Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
  • Legitimate administrator sets up autorun keys for legitimate reason

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.