Windows Suspicious Debugger Registration via Image File Execution Options
Alerts on Windows attempts to set Image File Execution Options debuggers for logon screen binaries via command-line arguments.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro (SigmaHQ), DRL 1.1
- Published
- 2019-09-06
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation events whose command line includes the Image File Execution Options debugger registration path and targets common Windows logon screen binaries (e.g., sethc.exe, utilman.exe, osk.exe). Attackers use this technique to redirect the execution of trusted executables to a debugger-controlled program, enabling persistence and privilege escalation. The detection relies on process creation telemetry and string matching in the CommandLine field for both the registration path and the affected binaries.
Reporting behind it
- blogs.technet.microsoft.comhttps://blogs.technet.microsoft.com/jonathantrull/2016/10/03/detecting-sticky-key-backdoors/
- bazaar.abuse.chhttps://bazaar.abuse.ch/sample/6f3aa9362d72e806490a8abce245331030d1ab5ac77e400dd475748236a6cc81/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_registry_install_reg_debugger_backdoor.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Suspicious Debugger Registration via Image File Execution Options
id: 32034020-d6b0-4af6-8b8a-e481fe036501
status: test
description: This rule flags process creation events whose command line includes the Image File Execution Options debugger registration path and targets common Windows logon screen binaries (e.g., sethc.exe, utilman.exe, osk.exe). Attackers use this technique to redirect the execution of trusted executables to a debugger-controlled program, enabling persistence and privilege escalation. The detection relies on process creation telemetry and string matching in the CommandLine field for both the registration path and the affected binaries.
references:
- https://blogs.technet.microsoft.com/jonathantrull/2016/10/03/detecting-sticky-key-backdoors/
- https://bazaar.abuse.ch/sample/6f3aa9362d72e806490a8abce245331030d1ab5ac77e400dd475748236a6cc81/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_registry_install_reg_debugger_backdoor.yml
author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule Team
date: 2019-09-06
modified: 2022-08-06
tags:
- attack.persistence
- attack.privilege-escalation
- attack.t1546.008
logsource:
category: process_creation
product: windows
detection:
selection1:
CommandLine|contains: \CurrentVersion\Image File Execution Options\
selection2:
CommandLine|contains:
- sethc.exe
- utilman.exe
- osk.exe
- magnify.exe
- narrator.exe
- displayswitch.exe
- atbroker.exe
- HelpPane.exe
condition: all of selection*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: ae215552-081e-44c7-805f-be16f975c8a2
type: derived