Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter

Alerts on RunMRU registry updates containing '#' plus excessive unusual Unicode spaces that may conceal command text.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-11-04
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows registry RunMRU entries where the stored path includes the Explorer RunMRU base, a details field containing the '#' character, and a large set of unusual space-like Unicode characters. Attackers may use non-standard spacing to obscure command content when viewed in Windows UI elements, increasing the chance that malicious execution strings are overlooked. Telemetry required is registry set activity capturing both the RunMRU key path and the corresponding details value contents.

Related detections9 linkedT1204 — drag to rearrange
Windows Process Creation: File Upload Clickfix Lure via Browser to Command Execution
Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Windows Registry: Suspicious Space-Padded TypedPaths Details String
Windows Registry Set: FileFix-style Command Evidence in TypedPaths url1
Obfuscated Paste-and-Run Execution From the Windows Run Dialog (via process_creation)
Malicious Remote Script Piped to a Shell on macOS (via process_creation)
ClickFix Paste-Jacking Execution of mshta Retrieving Remote Payload (via process_creation)
Malicious Edge Abuse for Payload Download via Console (via process_creation)
PowerShell Command-Line Obfuscation Constructs (via process_creation)
Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Pivot detection · T1204 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.