Windows Registry RunMRU Key Deletion

Alerts on deletion of the Windows Run dialog command history (RunMRU) registry key.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_delete
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-09-25
Updated
2026-07-30
title: Windows Registry RunMRU Key Deletion
id: 24e82e6b-8d14-46ac-8e48-389ee29a0302
related:
  - id: c11aecef-9c37-45a6-9c07-bc0782f963fd
    type: similar
  - id: 3a9b8c1e-5b2e-4f7a-9d1c-2a7f3b6e1c55
    type: derived
status: experimental
description: This rule flags attempts to delete the RunMRU registry key under Explorer, which stores the history of commands entered via the Windows Run dialog. Removing this key can reduce forensic evidence after an attacker has executed commands through that interface. The detection relies on registry deletion telemetry matching the target registry path ending with \Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU.
references:
  - https://www.zscaler.com/blogs/security-research/coldriver-updates-arsenal-baitswitch-and-simplefix
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_delete/registry_delete_runmru.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-09-25
tags:
  - attack.stealth
  - attack.t1070.003
logsource:
  category: registry_delete
  product: windows
detection:
  selection:
    TargetObject|endswith: \Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
  condition: selection
falsepositives:
  - Unknown
level: high
regression_tests_path: regression_data/rules/windows/registry/registry_delete/registry_delete_runmru/info.yml
license: DRL-1.1