Windows Registry: New IFilter Registration via PersistentHandler/CLSID Keys

Flags registry writes that register new Windows Search IFilters/persistent handlers via PersistentHandler and CLSID key patterns.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-21
Updated
2026-07-30

What it detects

This rule identifies Windows attempts to register new content extraction components for Windows Search by writing registry entries under PersistentHandler and related CLSID paths. Attackers can abuse IFilters to extend indexing for attacker-controlled file types and support persistence and execution chains leveraging search-related processing. It relies on registry_set telemetry that records TargetObject writes containing the expected PersistentHandler and CLSID key patterns and matches them against a set of known default persistent handler CLSIDs to reduce noise.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.