Windows Security: Suspicious Registry Access to ADHealthAgent Health Service Agent Keys

Detects non-standard processes accessing HKLM\SOFTWARE\Microsoft\ADHealthAgent registry key activity in Windows security logs.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC (SigmaHQ), DRL 1.1
Published
2021-08-26
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows security events where an access attempt targets registry key objects under HKLM:\SOFTWARE\Microsoft\ADHealthAgent, including the key’s values and sub-keys. An attacker could leverage access to AD Health service agent information to support abuse of cloud-connected features such as federation, depending on what the agent exposes. The detection relies on SACL-enabled registry auditing and security events 4656 and 4663, filtering out activity from specific Microsoft.Identity.Health AD FS agent processes.

Related detections9 linkedT1012 — drag to rearrange
Registry Query for WDigest
Suspicious Installed Software Enumeration via Registry Uninstall Key Query
Windows WMI StdRegProv Registry Enumeration via wmic.exe
PowerShell Registry Reconnaissance Indicators on Windows via Script Block Logging
Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Windows Security: Access to Azure AD Health Monitoring Agent Registry Key
Windows Regedit Exports Registry Hives to Files
Windows Registry Key Export via regedit.exe (-E) to File
Windows Security: checkadmin.exe TargetUserName starting with Administr (Event ID 4799)
Windows Security: Suspicious Registry Access to ADHealthAgent Health Service Agent Keys
Pivot detection · T1012 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.