Windows Registry Session Manager ASEP Modification via Auto-Start Extensibility Points
Flags registry modifications to Session Manager autostart extensibility points under CurrentControlSet\Control\Session Manager.
FreeUnreviewedSigmamediumv1
windows-registry-session-manager-asep-modification-via-auto-start-extensibility--046218bd
title: Windows Registry Session Manager ASEP Modification via Auto-Start Extensibility Points
id: 1b41d5e8-b2c9-4fe7-857a-d6256a2a4fd1
related:
- id: 17f878b8-9968-4578-b814-c4217fc5768c
type: obsolete
- id: 046218bd-e0d8-4113-a3c3-895a12b2b298
type: derived
status: test
description: This rule identifies changes to Session Manager autorun extensibility point registry locations under the CurrentControlSet\Control\Session Manager path. Attackers can use these keys to establish persistence by having the operating system execute attacker-controlled commands or load attacker-controlled components during boot or session initialization. Telemetry required is Windows registry set activity that captures the TargetObject path being modified.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
- https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_session_manager.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.001
- attack.t1546.009
logsource:
category: registry_set
product: windows
detection:
session_manager_base:
TargetObject|contains: \System\CurrentControlSet\Control\Session Manager
session_manager:
TargetObject|contains:
- \SetupExecute
- \S0InitialCommand
- \KnownDlls
- \Execute
- \BootExecute
- \AppCertDlls
filter:
Details: (Empty)
condition: session_manager_base and session_manager and not filter
falsepositives:
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1
What it detects
This rule identifies changes to Session Manager autorun extensibility point registry locations under the CurrentControlSet\Control\Session Manager path. Attackers can use these keys to establish persistence by having the operating system execute attacker-controlled commands or load attacker-controlled components during boot or session initialization. Telemetry required is Windows registry set activity that captures the TargetObject path being modified.
Known false positives
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.