Windows Registry: Suspicious Space-Padded TypedPaths Details String

Alerts on registry writes to TypedPaths url1 where Details includes “#” plus unusual Unicode space padding.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-11-04
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags registry set activity targeting the Explorer TypedPaths url1 entry when the Details field contains a fragment marker and a high density of space-like Unicode characters. Attackers may use visually subtle spacing to obscure malicious content or execution paths from casual review. The detection relies on Windows registry set telemetry capturing the TargetObject and Details values written under TypedPaths.

Related detections9 linkedT1204 — drag to rearrange
Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Malicious Edge Abuse for Payload Download via Console (via process_creation)
PowerShell Command-Line Obfuscation Constructs (via process_creation)
Obfuscated Edge/Chrome Headless Feature Abuse for Payload Download (via process_creation)
Windows Process Creation: Python One-Liners Decoding Base64 via Command Line
Linux Process Execution of Python Base64 Decode One-Liners
Windows Process Creation: File Upload Clickfix Lure via Browser to Command Execution
Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Windows Registry: Suspicious Space-Padded TypedPaths Details String
Pivot detection · T1204 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.