Windows Registry Set Detection of Suspicious Environment Variable Commands

Flags Windows registry environment variable registrations that include PowerShell and base64-encoded command fragments.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-12-20
Updated
2026-07-30

What it detects

This rule identifies registry writes that register environment variables containing the \Environment path and suspicious command or encoded string content. Attackers may use environment variables to establish persistence or stealth by injecting PowerShell/Invoke-related commands or base64-encoded payload fragments that execute later. It relies on Windows registry set telemetry, specifically matching TargetObject values and suspicious patterns in the Details field.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.