Windows Registry Persistence: DbgManagedDebugger Debugger Value Added

Alerts on registry sets that add a Debugger value under DbgManagedDebugger, indicating potential crash-triggered persistence.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-08-07
Updated
2026-07-30
title: "Windows Registry Persistence: DbgManagedDebugger Debugger Value Added"
id: 59978f15-b3a5-451f-a57b-105873098159
status: test
description: This rule flags when a Windows registry value named "Debugger" is set under the \Microsoft\.NETFramework\DbgManagedDebugger key. Adding this entry can create application-crash-triggered code execution, which attackers may leverage for persistence or stealth. The detection relies on registry set telemetry that records the targeted registry path and associated value information, and excludes entries matching a specific vsjitdebugger.exe debug configuration pattern.
references:
  - https://www.hexacorn.com/blog/2013/09/19/beyond-good-ol-run-key-part-4/
  - https://github.com/last-byte/PersistenceSniper
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_dbgmanageddebugger_persistence.yml
author: frack113, Huntrule Team
date: 2022-08-07
modified: 2023-08-17
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.execution
  - attack.stealth
  - attack.t1574
logsource:
  category: registry_set
  product: windows
detection:
  selection:
    TargetObject|endswith: \Microsoft\.NETFramework\DbgManagedDebugger
  filter:
    Details: '"C:\Windows\system32\vsjitdebugger.exe" PID %d APPDOM %d EXTEXT "%s" EVTHDL %d'
  condition: selection and not filter
falsepositives:
  - Legitimate use of the key to setup a debugger. Which is often the case on developers machines
level: medium
license: DRL-1.1
related:
  - id: 9827ae57-3802-418f-994b-d5ecf5cd974b
    type: derived