Windows Registry Tampering: Attachment Manager Associations Default File Type Risk and LowRiskFileTypes

Flags Windows registry changes to Attachment Manager associations that set DefaultFileTypeRisk and modify LowRiskFileTypes.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-01
Updated
2026-07-30

What it detects

This rule identifies registry tampering under the Attachment Manager associations policy path by matching specific values for DefaultFileTypeRisk and LowRiskFileTypes. Attackers may reduce user visibility or security protections by altering how Windows classifies and handles file types associated with attachments. It relies on registry set telemetry capturing writes to TargetObject values and their associated DWORD/data contents.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.