Windows Registry: SentinelOne Scan Context Menu Command Tampering by Non-SentinelOne Process

Alerts on registry modifications to SentinelOne scan context menu command entries not matching SentinelOne’s expected binary.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-03-06
Updated
2026-07-30

What it detects

This rule flags registry updates to the SentinelOne Scan context menu command path when the recorded command details do not correspond to the SentinelOne default scan binary location. Attackers can persist or hijack context menu behavior by modifying these command entries so the next user action runs attacker-controlled code. It relies on Windows registry set telemetry capturing changes under the SentinelOne scan command registry path and the writing process details (image path and command details).

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.