Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell

Alerts when reg.exe or PowerShell modifies User Shell Folders/Shell Folders Startup-related registry values.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-01-05
Updated
2026-07-30

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creations where reg.exe or PowerShell is used with command-line actions consistent with adding or setting registry values under the User Shell Folders / Shell Folders keys. It specifically looks for command lines referencing the Shell Folders paths and a Startup-related suffix, which can indicate attempts to influence what runs automatically. The detection relies on Windows process creation telemetry, including the executable image name and command-line contents.

Related detections9 linkedT1547.001 — drag to rearrange
Suspicious NTUSER.MAN Mandatory Profile File Created for Logon Persistence (via file_event)
Windows Registry EventLog ChannelAccess SDDL Tampering Detection
Malicious Enabling of Restricted Admin Mode via Registry by UAT-8837
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Suspicious Autorun Registry Persistence via sausageLoop Run Key
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious BabyLockerKZ Run Key Persistence
Suspicious Run Key Persistence Pointing To User-Writable Path
Malicious Ctrlpanel Run Key Autostart Persistence (via registry_set)
Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell
Pivot detection · T1547.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.