Windows Registry Persistence via Image File Execution Options GlobalFlag and SilentProcessExit

Flags registry changes to IFEO GlobalFlag and SilentProcessExit keys that can enable stealthy persistence or process redirection.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Karneades, Jonhnathan Ribeiro, Florian Roth (SigmaHQ), DRL 1.1
Published
2018-04-11
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies Windows registry persistence attempts by matching Image File Execution Options subkeys containing GlobalFlag and SilentProcessExit-related configuration values. Such behavior can be used to alter how processes start or fail in a way that reduces visibility to defenders. The detection relies on registry set telemetry, specifically TargetObject strings containing the expected key paths and value names.

Related detections5 linkedT1546.012 — drag to rearrange
Suspicious Image File Execution Options Debugger Hijack (via registry_set)
Malicious IFEO Debugger Hijack of vds.exe by FishMonger
Suspicious Image File Execution Options Debugger Hijack by Miner Campaign
Suspicious Command Processor AutoRun Persistence via Registry Set
Windows Registry App Paths Default Property Change Using Suspicious Values
Windows Registry Persistence via Image File Execution Options GlobalFlag and SilentProcessExit
Pivot detection · T1546.012 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.