Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text

Alerts on registry changes to Windows legal notice caption/text containing ransomware-style keywords.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-12-11
Updated
2026-07-30

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags modifications to the Windows “LegalNoticeCaption” and “LegalNoticeText” registry values when the new message contains ransomware-associated keywords such as “encrypted,” “Unlock-Password,” or “paying.” Attackers may use these text fields to display ransom-style instructions to users immediately upon login or session access. The detection relies on Windows registry set telemetry capturing the target value path and the updated content.

Related detections3 linkedT1491.001 — drag to rearrange
Windows Registry Change to Desktop Wallpaper Policy or Settings
Windows reg.exe Changes Desktop Background Policy Values
Windows PowerShell Wallpaper Replacement via Registry and SystemParametersInfo
Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text
Pivot detection · T1491.001 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.