Windows Registry WinSock2 Autostart Extensibility Point Modification
Flags registry modifications to WinSock2 Parameters catalog entries consistent with persistence via ASEP.
- Product
- windows
- Category
- registry_set
- Author
- Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split) (SigmaHQ), DRL 1.1
- Published
- 2019-10-25
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies registry changes to the WinSock2 Parameters autostart extensibility point under Session/Protocol/Namespace catalog entries. Attackers can use WinSock2-related persistence points to influence network-related behavior across reboots. It relies on registry set telemetry matching TargetObject paths for WinSock2 Parameters and the specific Catalog_Entries subkeys, excluding events where the modifying Image is MSI installer executable paths.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
- learn.microsoft.comhttps://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- gist.github.comhttps://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_winsock2.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Registry WinSock2 Autostart Extensibility Point Modification
id: 3610c2bd-f7be-4046-8c65-ad75977d1fe5
related:
- id: 17f878b8-9968-4578-b814-c4217fc5768c
type: derived
- id: d6c2ce7e-afb5-4337-9ca4-4b5254ed0565
type: derived
status: test
description: This rule identifies registry changes to the WinSock2 Parameters autostart extensibility point under Session/Protocol/Namespace catalog entries. Attackers can use WinSock2-related persistence points to influence network-related behavior across reboots. It relies on registry set telemetry matching TargetObject paths for WinSock2 Parameters and the specific Catalog_Entries subkeys, excluding events where the modifying Image is MSI installer executable paths.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
- https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_winsock2.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.001
logsource:
category: registry_set
product: windows
detection:
winsock_parameters_base:
TargetObject|contains: \System\CurrentControlSet\Services\WinSock2\Parameters
winsock_parameters:
TargetObject|contains:
- \Protocol_Catalog9\Catalog_Entries
- \NameSpace_Catalog5\Catalog_Entries
filter:
- Details: (Empty)
- Image: C:\Windows\System32\MsiExec.exe
- Image: C:\Windows\syswow64\MsiExec.exe
condition: winsock_parameters_base and winsock_parameters and not filter
falsepositives:
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1