Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)

Alerts when DsrmAdminLogonBehavior registry value is changed on Windows, except the default DWORD 0x00000000.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nischal Khadgi (SigmaHQ), DRL 1.1
Published
2024-07-11
Updated
2026-07-30

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags registry modifications to the DsrmAdminLogonBehavior value under \Control\Lsa, excluding the default DWORD value of 0x00000000. Changing this setting can alter how the DSRM local administrator account can be used during Domain Controller boot and service states. Attackers may abuse DSRM-related credentials and restore-mode access for persistence or to impair defensive recovery paths. The detection relies on Windows registry set events targeting the specific value path.

Related detections9 linkedT1556 — drag to rearrange
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
Suspicious AWS SAML Identity Provider Creation
Suspicious Okta Sign-On Policy Lifecycle Modification
Possible Shadow Credentials Abuse via msDS-KeyCredentialLink Modification
Azure AD Audit: Trusted Root CA Added for Passwordless Certificate Authentication
Azure AD Audit Logs: Certificate-based authentication enabled via AuthenticationMethodsPolicy update
AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
GitHub Audit: High-Risk Security Controls Disabled
Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object
Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)
Pivot detection · T1556 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.