Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators

Alerts on Windows RunMRU registry changes containing HTTP/HTTPS URLs plus captcha/automation or command execution indicators.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-03-25
Updated
2026-07-30

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows registry Set operations targeting Explorer RunMRU entries where the stored Details contain HTTP or HTTPS URLs. It further narrows matches to entries that include common fake-interaction and automation-bypass terms (for example, captcha/challenge/verification) and/or strings associated with command or scripting execution tools (such as PowerShell, cmd, mshta, certutil, curl, wget, and mshta). This combination matters because it can reflect user-driven phishing lure workflows that lead to pasting and executing attacker-controlled content via the Run dialog. The detection relies on registry_set telemetry for RunMRU TargetObject and the presence of specific URL and keyword patterns in the Details field.

Related detections9 linkedT1204.001 — drag to rearrange
Suspicious Script Interpreter Spawned by Explorer via ClickFix Run Dialog (via process_creation)
Suspicious Masqueraded Windows Update Python Script Execution
ClickFix Pastejacking via Script Interpreter Command in Run Dialog MRU (via registry_set)
Suspicious cscript Execution of JavaScript Spawned by PowerShell
Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)
Suspicious Renamed MySQL Binary Executed from Temp via ClickFix (via process_creation)
Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Linux Command Lines Creating Symlink to /etc/passwd
Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
Pivot detection · T1204.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.