Windows Registry Modification of Internet Explorer Autostart Extension Keys (ASEP)
Flags Windows registry changes to Internet Explorer ASEP extension/toolbar keys associated with persistence.
FreeUnreviewedSigmamediumv1
windows-registry-modification-of-internet-explorer-autostart-extension-keys-asep-a80f662f
title: Windows Registry Modification of Internet Explorer Autostart Extension Keys (ASEP)
id: a09ccc8c-096b-46af-a8c8-8a3e6ed2d297
related:
- id: 17f878b8-9968-4578-b814-c4217fc5768c
type: obsolete
- id: a80f662f-022f-4429-9b8c-b1a41aaa6688
type: derived
status: test
description: This rule identifies registry changes targeting Internet Explorer AutoStart Extensibility Point (ASEP) locations under the 32-bit and 64-bit Internet Explorer keys. It focuses on extension and toolbar-related subkeys that attackers may use to persist or execute code within Internet Explorer. The detection relies on registry set events and matches the TargetObject path components, while excluding specific known extension and toolbar layouts that commonly cause benign results. It also filters out empty Details entries to reduce noise.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
- https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_internet_explorer.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.001
logsource:
category: registry_set
product: windows
detection:
ie:
TargetObject|contains:
- \Software\Wow6432Node\Microsoft\Internet Explorer
- \Software\Microsoft\Internet Explorer
ie_details:
TargetObject|contains:
- \Toolbar
- \Extensions
- \Explorer Bars
filter_empty:
Details: (Empty)
filter_extensions:
TargetObject|contains:
- \Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}
- \Extensions\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}
- \Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
- \Extensions\{A95fe080-8f5d-11d2-a20b-00aa003c157a}
filter_toolbar:
TargetObject|endswith:
- \Toolbar\ShellBrowser\ITBar7Layout
- \Toolbar\ShowDiscussionButton
- \Toolbar\Locked
condition: ie and ie_details and not 1 of filter_*
falsepositives:
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1
What it detects
This rule identifies registry changes targeting Internet Explorer AutoStart Extensibility Point (ASEP) locations under the 32-bit and 64-bit Internet Explorer keys. It focuses on extension and toolbar-related subkeys that attackers may use to persist or execute code within Internet Explorer. The detection relies on registry set events and matches the TargetObject path components, while excluding specific known extension and toolbar layouts that commonly cause benign results. It also filters out empty Details entries to reduce noise.
Known false positives
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.