Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators

Alerts on Windows Filtering Platform policy change events containing "RonPolicy" consistent with NoFilter abuse.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Stamatis Chatzimangou (st0pp3r) (SigmaHQ), DRL 1.1
Published
2024-01-05
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows Security events related to filtering platform policy changes where fields contain the indicator 'RonPolicy'. It is intended to catch activity consistent with the NoFilter tool, which targets Windows Filtering Platform behavior as part of a privilege escalation technique. The detection relies on Security log events 5447 and 5449 and string matching on FilterName and ProviderContextName.

Related detections9 linkedT1134.001 — drag to rearrange
Malicious Potato Family Privilege Escalation Tool Execution (via process_creation)
Masquerading Cobalt Strike GetSystem Named-Pipe Impersonation Pattern (via process_creation)
Malicious Named Pipe kesknq for Token Impersonation (via pipe_created)
Suspicious New Rights Granted to an Account for Privilege Escalation (via security)
SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
SharpImpersonation Tool Execution on Windows
Windows Process Creation: Impersonate.exe HackTool Execution
Windows Security 4624 LogonType 9 Impersonation via Negotiate (Advapi) Token Abuse Indicator
Windows: Detect Named Pipe Creation with Koh Default Names
Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators
Pivot detection · T1134.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.