Windows Registry SIP Persistence via New Cryptography Provider Registration

Detects suspicious Windows registry writes that register a new SIP/Cryptography provider DLL for persistence or defense impairment.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-21
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags registry activity consistent with registering or updating a Security Information Provider (SIP) by targeting Cryptography provider and EncodingType keys. Attackers may use SIP changes to influence trust decisions or impede defense mechanisms by persisting malicious trust-related configuration. It relies on Windows registry set telemetry matching specific provider-related registry paths and SIP-related DLL string patterns, while excluding known legitimate provider details and suppressing events involving poqexec and CryptSIPDll.

Related detections2 linkedT1553.003 — drag to rearrange
SIP or Trust Provider Registration (via registry_set)
Windows Registry Seed Value Set Under Cryptography\Providers (Kapeka SIP Persistence)
Windows Registry SIP Persistence via New Cryptography Provider Registration
Pivot detection · T1553.003 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.