Windows Registry Set Detection of Suspicious Environment Variable Commands

Flags Windows registry environment variable registrations that include PowerShell and base64-encoded command fragments.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-12-20
Updated
2026-07-30
title: Windows Registry Set Detection of Suspicious Environment Variable Commands
id: 78d7dcd5-42db-4326-889c-4b3a5715d681
status: test
description: This rule identifies registry writes that register environment variables containing the \Environment path and suspicious command or encoded string content. Attackers may use environment variables to establish persistence or stealth by injecting PowerShell/Invoke-related commands or base64-encoded payload fragments that execute later. It relies on Windows registry set telemetry, specifically matching TargetObject values and suspicious patterns in the Details field.
references:
  - https://infosec.exchange/@sbousseaden/109542254124022664
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_suspicious_env_variables.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-12-20
modified: 2023-08-17
tags:
  - attack.persistence
  - attack.stealth
logsource:
  product: windows
  category: registry_set
detection:
  selection_main:
    TargetObject|contains: \Environment\
  selection_details:
    - Details:
        - powershell
        - pwsh
    - Details|contains:
        - \AppData\Local\Temp\
        - C:\Users\Public\
        - TVqQAAMAAAAEAAAA
        - TVpQAAIAAAAEAA8A
        - TVqAAAEAAAAEABAA
        - TVoAAAAAAAAAAAAA
        - TVpTAQEAAAAEAAAA
        - SW52b2tlL
        - ludm9rZS
        - JbnZva2Ut
        - SQBuAHYAbwBrAGUALQ
        - kAbgB2AG8AawBlAC0A
        - JAG4AdgBvAGsAZQAtA
    - Details|startswith:
        - SUVY
        - SQBFAF
        - SQBuAH
        - cwBhA
        - aWV4
        - aQBlA
        - R2V0
        - dmFy
        - dgBhA
        - dXNpbm
        - H4sIA
        - Y21k
        - cABhAH
        - Qzpc
        - Yzpc
  condition: all of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 966315ef-c5e1-4767-ba25-fce9c8de3660
    type: derived