Windows Registry Set in Shell Open Command Using PowerShell Cryptography .NET Classes

Flags registry set of \Shell\Open\Command where PowerShell references System.Security.Cryptography crypto classes.

FreeReviewedSigma · Medium · v5
Product
windows
Category
registry_set
Author
Andreas Braathen (mnemonic.io) (SigmaHQ), DRL 1.1
Published
2023-12-01
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags registry value updates to the "\Shell\Open\Command" location where the value details reference PowerShell (powershell/pwsh) and .NET cryptography classes from System.Security.Cryptography. The behavior matters because attackers can embed cryptographic classes in PowerShell-driven command strings to support on-the-fly encryption/decryption for stealth or payload handling. It relies on registry set telemetry that includes the registry TargetObject path and the Details content where the PowerShell executable and specific cryptography class names appear.

Related detections9 linkedT1059.001 — drag to rearrange
PowerShell Command-Line Obfuscation Constructs (via process_creation)
Windows PowerShell Obfuscated COM MSI Installation via WindowsInstaller.Installer
PowerShell Crypto Namespace Class Invocation for Windows Process Creation
Suspicious Script Interpreter Spawned by Explorer via ClickFix Run Dialog (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Suspicious Autorun Registry Persistence via sausageLoop Run Key
Malicious BabyLockerKZ Run Key Persistence
Suspicious Run Key Persistence Pointing To User-Writable Path
Malicious Ctrlpanel Run Key Autostart Persistence (via registry_set)
Windows Registry Set in Shell Open Command Using PowerShell Cryptography .NET Classes
Pivot detection · T1059.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.