Windows Registry: Wow6432Node Classes Autorun/ASEP Key Modification via ShellEx/CLSID Paths
Alerts on registry writes to Wow6432Node Classes ASEP-related ShellEx/CLSID key paths commonly used for persistence.
FreeUnreviewedSigmamediumv1
windows-registry-wow6432node-classes-autorun-asep-key-modification-via-shellex-c-18f2065c
title: "Windows Registry: Wow6432Node Classes Autorun/ASEP Key Modification via ShellEx/CLSID Paths"
id: 384c2a52-21b3-4df5-a45f-23736b801df2
related:
- id: 17f878b8-9968-4578-b814-c4217fc5768c
type: obsolete
- id: 18f2065c-d36c-464a-a748-bcf909acb2e3
type: derived
status: test
description: This rule flags registry set activity where the modified key path contains the Wow6432Node Classes directory and matches specific Autorun extensibility point (ASEP) locations (e.g., ShellEx and CLSID instance keys). Attackers often abuse these registry extensibility points to establish persistence by having malicious code load when Windows Explorer or related shell components access the configured handlers. The detection relies on registry set telemetry capturing the target registry object path (TargetObject) for the write operation.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md
- https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns
- https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_wow6432node_classes.yml
author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule Team
date: 2019-10-25
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1547.001
logsource:
category: registry_set
product: windows
detection:
wow_classes_base:
TargetObject|contains: \Software\Wow6432Node\Classes
wow_classes:
TargetObject|contains:
- \Folder\ShellEx\ExtShellFolderViews
- \Folder\ShellEx\DragDropHandlers
- \Folder\ShellEx\ColumnHandlers
- \Directory\Shellex\DragDropHandlers
- \Directory\Shellex\CopyHookHandlers
- \CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance
- \CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance
- \CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
- \CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
- \AllFileSystemObjects\ShellEx\DragDropHandlers
- \ShellEx\PropertySheetHandlers
- \ShellEx\ContextMenuHandlers
filter:
Details: (Empty)
condition: wow_classes_base and wow_classes and not filter
falsepositives:
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
level: medium
license: DRL-1.1
What it detects
This rule flags registry set activity where the modified key path contains the Wow6432Node Classes directory and matches specific Autorun extensibility point (ASEP) locations (e.g., ShellEx and CLSID instance keys). Attackers often abuse these registry extensibility points to establish persistence by having malicious code load when Windows Explorer or related shell components access the configured handlers. The detection relies on registry set telemetry capturing the target registry object path (TargetObject) for the write operation.
Known false positives
- Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
- Legitimate administrator sets up autorun keys for legitimate reason
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.