Windows Registry Set: FileFix-style Command Evidence in TypedPaths url1

Flags Windows registry TypedPaths url1 updates containing URL fragments and command/script keywords consistent with FileFix behavior.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Alfie Champion (delivr.to), Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-07-05
Updated
2026-07-30

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule looks for registry updates to the Explorer TypedPaths value url1, where the data contains both a URL indicator ('#' and 'http') and a set of execution-related command or scripting keywords. The presence of these command strings alongside URL fragments can indicate an attempt to embed or evidence user targeting consistent with the FileFix technique. It relies on registry_set telemetry that records the TargetObject path and the modified Details content for TypedPaths values.

Related detections9 linkedT1204 — drag to rearrange
Windows Process Creation: File Upload Clickfix Lure via Browser to Command Execution
Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Obfuscated Paste-and-Run Execution From the Windows Run Dialog (via process_creation)
Malicious Remote Script Piped to a Shell on macOS (via process_creation)
ClickFix Paste-Jacking Execution of mshta Retrieving Remote Payload (via process_creation)
Malicious Edge Abuse for Payload Download via Console (via process_creation)
Obfuscated Edge/Chrome Headless Feature Abuse for Payload Download (via process_creation)
Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Windows Registry Set: FileFix-style Command Evidence in TypedPaths url1
Pivot detection · T1204 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.