Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Alerts on RunMRU registry updates containing '#' plus excessive unusual Unicode spaces that may conceal command text.
- Product
- windows
- Category
- registry_set
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2025-11-04
- Updated
- 2026-07-30
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows registry RunMRU entries where the stored path includes the Explorer RunMRU base, a details field containing the '#' character, and a large set of unusual space-like Unicode characters. Attackers may use non-standard spacing to obscure command content when viewed in Windows UI elements, increasing the chance that malicious execution strings are overlooked. Telemetry required is registry set activity capturing both the RunMRU key path and the corresponding details value contents.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
id: 56ededc0-6bd7-4755-a5e1-ab95b677f10f
related:
- id: 3ae9974a-eb09-4044-8e70-8980a50c12c8
type: similar
- id: 7a1b4c5e-8f3d-4b9a-7c2e-1f4a5b8c6d9e
type: derived
status: experimental
description: This rule flags Windows registry RunMRU entries where the stored path includes the Explorer RunMRU base, a details field containing the '#' character, and a large set of unusual space-like Unicode characters. Attackers may use non-standard spacing to obscure command content when viewed in Windows UI elements, increasing the chance that malicious execution strings are overlooked. Telemetry required is registry set activity capturing both the RunMRU key path and the corresponding details value contents.
references:
- https://expel.com/blog/cache-smuggling-when-a-picture-isnt-a-thousand-words/
- https://github.com/JohnHammond/recaptcha-phish
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_susp_runmru_space_character.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-11-04
tags:
- attack.execution
- attack.stealth
- attack.t1204.004
- attack.t1027.010
logsource:
category: registry_set
product: windows
detection:
selection_key:
TargetObject|contains: \Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\
Details|contains: "#"
selection_space_variation:
Details|contains:
-
-
-
-
-
-
-
-
-
-
-
-
- " "
condition: all of selection_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1