Windows Registry User Profile Creation: ANONYMOUS _DomainUser_ Entries in ProfileList

Alerts on ProfileList registry writes indicating a new user profile with 'ANONYMOUS' and '_DomainUser_' markers.

FreeReviewedSigma · High · v5
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-02
Updated
2026-07-31

What it detects

This rule flags registry changes under Windows ProfileList paths that include a ProfileImagePath containing both the strings "ANONYMOUS" and "_DomainUser_". Creating or altering user profile entries in the registry can be used by malware to establish persistence or masquerade as legitimate user context. It relies on registry-set telemetry capturing TargetObject paths and their associated Details content.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.