Windows Registry Run Key Persistence Using Small Sieve Typo Value Strings

Flags registry Run-key writes on Windows with Small Sieve-specific typo and executable detail strings in value data.

FreeReviewedSigma · High · v5
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-19
Updated
2026-07-31

What it detects

This rule flags Windows registry modifications that create or update Run key entries containing specific, intentionally misspelled value components and a recognizable “.exe Platypus” details string. Such persistence enables malware to launch on user login, and the unusual typo acts as an identifiable marker for this behavior. Telemetry relies on registry set events capturing the TargetObject and associated TargetObject/Details contents.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.