Windows Registry Persistence Indicators for NetWire-Related Keys
Flags newly added Windows registry keys with paths containing \\software\\NetWire, consistent with potential NetWire-related persistence.
FreeUnreviewedSigmahighv1
windows-registry-persistence-indicators-for-netwire-related-keys-1d218616
title: Windows Registry Persistence Indicators for NetWire-Related Keys
id: bf20860a-593b-46e1-9159-d5792b02a143
status: test
description: This rule matches Windows registry additions where the target key path contains "\software\NetWire". Attackers commonly use registry storage to establish persistence or maintain malware configuration across user logons. The detection relies on registry add telemetry capturing the TargetObject field for newly created keys.
references:
- https://www.fortinet.com/blog/threat-research/new-netwire-rat-variant-spread-by-phishing
- https://resources.infosecinstitute.com/topic/netwire-malware-what-it-is-how-it-works-and-how-to-prevent-it-malware-spotlight/
- https://unit42.paloaltonetworks.com/guloader-installing-netwire-rat/
- https://blogs.blackberry.com/en/2021/09/threat-thursday-netwire-rat-is-coming-down-the-line
- https://app.any.run/tasks/41ecdbde-4997-4301-a350-0270448b4c8f/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Malware/Netwire/registry_add_malware_netwire.yml
author: Christopher Peacock, Huntrule Team
date: 2021-10-07
modified: 2025-11-03
tags:
- attack.persistence
- attack.defense-impairment
- attack.t1112
- detection.emerging-threats
logsource:
product: windows
category: registry_add
detection:
selection:
TargetObject|contains: \software\NetWire
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 1d218616-71b0-4c40-855b-9dbe75510f7f
type: derived
What it detects
This rule matches Windows registry additions where the target key path contains "\software\NetWire". Attackers commonly use registry storage to establish persistence or maintain malware configuration across user logons. The detection relies on registry add telemetry capturing the TargetObject field for newly created keys.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.