Windows Registry: New W32Time TimeProvider DllName Values Set Under Services\W32Time\TimeProvider

Alerts on new or changed W32Time TimeProvider DllName registry values under Services\W32Time\TimeProvider.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-06-19
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags registry updates that create or modify a W32Time TimeProvider entry with a DLL name under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProvider. Attackers may abuse Windows Time service configuration to have a specified DLL loaded during system boot or time-provider initialization. The detection relies on registry set telemetry capturing TargetObject paths and matching the end of the DllName value name, while filtering out a few known DLL entries.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.