Windows: Registry Set by Rundll32 for Screen Saver Execution via SCRNSAVE.EXE
Flags Windows registry sets where Rundll32 points SCRNSAVE.EXE to a .scr file.
- Product
- windows
- Category
- registry_set
- Author
- Jose Luis Sanchez Martinez (@Joseliyo_Jstnk) (SigmaHQ), DRL 1.1
- Published
- 2022-05-04
- Updated
- 2026-07-30
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies when Rundll32 is involved in creating a registry entry tied to the Control Panel\Desktop\SCRNSAVE.EXE setting, with Details indicating a .scr file. Such persistence or execution flow can be used by attackers to masquerade and load a screen saver payload. The detection relies on process image path suffix matching (rundll32.exe) and registry set telemetry that captures TargetObject and Details contents.
Reporting behind it
- twitter.comhttps://twitter.com/VakninHai/status/1517027824984547329
- twitter.comhttps://twitter.com/pabraeken/status/998627081360695297
- jstnk9.github.iohttps://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows: Registry Set by Rundll32 for Screen Saver Execution via SCRNSAVE.EXE"
id: 7fe54fb6-24f7-44c5-96aa-047c5f087e11
status: test
description: This rule identifies when Rundll32 is involved in creating a registry entry tied to the Control Panel\Desktop\SCRNSAVE.EXE setting, with Details indicating a .scr file. Such persistence or execution flow can be used by attackers to masquerade and load a screen saver payload. The detection relies on process image path suffix matching (rundll32.exe) and registry set telemetry that captures TargetObject and Details contents.
references:
- https://twitter.com/VakninHai/status/1517027824984547329
- https://twitter.com/pabraeken/status/998627081360695297
- https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml
author: Jose Luis Sanchez Martinez (@Joseliyo_Jstnk), Huntrule Team
date: 2022-05-04
modified: 2023-08-17
tags:
- attack.stealth
- attack.t1218.011
logsource:
product: windows
category: registry_set
detection:
selection:
Image|endswith: \rundll32.exe
registry:
TargetObject|contains: \Control Panel\Desktop\SCRNSAVE.EXE
Details|endswith: .scr
filter:
Details|contains:
- C:\Windows\System32\
- C:\Windows\SysWOW64\
condition: selection and registry and not filter
falsepositives:
- Legitimate use of screen saver
level: medium
license: DRL-1.1
related:
- id: 40b6e656-4e11-4c0c-8772-c1cc6dae34ce
type: derived