Windows Registry Modification of Internet Explorer Autostart Extension Keys (ASEP)

Flags Windows registry changes to Internet Explorer ASEP extension/toolbar keys associated with persistence.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split) (SigmaHQ), DRL 1.1
Published
2019-10-25
Updated
2026-07-30
title: Windows Registry Modification of Internet Explorer Autostart Extension Keys (ASEP)
id: a09ccc8c-096b-46af-a8c8-8a3e6ed2d297
related:
  - id: 17f878b8-9968-4578-b814-c4217fc5768c
    type: obsolete
  - id: a80f662f-022f-4429-9b8c-b1a41aaa6688
    type: derived
status: test
description: This rule identifies registry changes targeting Internet Explorer AutoStart Extensibility Point (ASEP) locations under the 32-bit and 64-bit Internet Explorer keys. It focuses on extension and toolbar-related subkeys that attackers may use to persist or execute code within Internet Explorer. The detection relies on registry set events and matches the TargetObject path components, while excluding specific known extension and toolbar layouts that commonly cause benign results. It also filters out empty Details entries to reduce noise.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
  - https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
  - https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_internet_explorer.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1547.001
logsource:
  category: registry_set
  product: windows
detection:
  ie:
    TargetObject|contains:
      - \Software\Wow6432Node\Microsoft\Internet Explorer
      - \Software\Microsoft\Internet Explorer
  ie_details:
    TargetObject|contains:
      - \Toolbar
      - \Extensions
      - \Explorer Bars
  filter_empty:
    Details: (Empty)
  filter_extensions:
    TargetObject|contains:
      - \Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}
      - \Extensions\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}
      - \Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
      - \Extensions\{A95fe080-8f5d-11d2-a20b-00aa003c157a}
  filter_toolbar:
    TargetObject|endswith:
      - \Toolbar\ShellBrowser\ITBar7Layout
      - \Toolbar\ShowDiscussionButton
      - \Toolbar\Locked
  condition: ie and ie_details and not 1 of filter_*
falsepositives:
  - Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
  - Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1