Windows Registry Screensaver Path Value Modified (SCRNSAVE.EXE)

Alerts on registry changes to the SCRNSAVE.EXE screensaver binary path under HKCU.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_event
Author
Bartlomiej Czyz @bczyz1, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-11
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags modifications to a Windows registry value that contains the configured screensaver binary path for HKEY_CURRENT_USER\Control Panel\Desktop\SCRNSAVE.EXE. Attackers can abuse screensaver execution to persist by redirecting the screensaver binary to attacker-controlled code. The detection relies on registry event telemetry matching the TargetObject ending in the SCRNSAVE.EXE registry path while excluding changes attributed to certain Image processes.

Related detections2 linkedT1546.002 — drag to rearrange
Windows: Suspicious .SCR Screensaver File Creation
Windows: Detect reg.exe Changing Screen Saver Registry Settings for .scr Payloads
Windows Registry Screensaver Path Value Modified (SCRNSAVE.EXE)
Pivot detection · T1546.002 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.