Windows Registry: Wow6432Node Classes Autorun/ASEP Key Modification via ShellEx/CLSID Paths

Alerts on registry writes to Wow6432Node Classes ASEP-related ShellEx/CLSID key paths commonly used for persistence.

FreeUnreviewedSigmamediumv1
title: "Windows Registry: Wow6432Node Classes Autorun/ASEP Key Modification via ShellEx/CLSID Paths"
id: 384c2a52-21b3-4df5-a45f-23736b801df2
related:
  - id: 17f878b8-9968-4578-b814-c4217fc5768c
    type: obsolete
  - id: 18f2065c-d36c-464a-a748-bcf909acb2e3
    type: derived
status: test
description: This rule flags registry set activity where the modified key path contains the Wow6432Node Classes directory and matches specific Autorun extensibility point (ASEP) locations (e.g., ShellEx and CLSID instance keys). Attackers often abuse these registry extensibility points to establish persistence by having malicious code load when Windows Explorer or related shell components access the configured handlers. The detection relies on registry set telemetry capturing the target registry object path (TargetObject) for the write operation.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
  - https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
  - https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_wow6432node_classes.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
  - attack.privilege-escalation
  - attack.persistence
  - attack.t1547.001
logsource:
  category: registry_set
  product: windows
detection:
  wow_classes_base:
    TargetObject|contains: \Software\Wow6432Node\Classes
  wow_classes:
    TargetObject|contains:
      - \Folder\ShellEx\ExtShellFolderViews
      - \Folder\ShellEx\DragDropHandlers
      - \Folder\ShellEx\ColumnHandlers
      - \Directory\Shellex\DragDropHandlers
      - \Directory\Shellex\CopyHookHandlers
      - \CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance
      - \CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance
      - \CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
      - \CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
      - \AllFileSystemObjects\ShellEx\DragDropHandlers
      - \ShellEx\PropertySheetHandlers
      - \ShellEx\ContextMenuHandlers
  filter:
    Details: (Empty)
  condition: wow_classes_base and wow_classes and not filter
falsepositives:
  - Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
  - Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1

What it detects

This rule flags registry set activity where the modified key path contains the Wow6432Node Classes directory and matches specific Autorun extensibility point (ASEP) locations (e.g., ShellEx and CLSID instance keys). Attackers often abuse these registry extensibility points to establish persistence by having malicious code load when Windows Explorer or related shell components access the configured handlers. The detection relies on registry set telemetry capturing the target registry object path (TargetObject) for the write operation.

Known false positives

  • Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
  • Legitimate administrator sets up autorun keys for legitimate reason

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.