Windows Suspicious Debugger Registration via Image File Execution Options

Alerts on Windows attempts to set Image File Execution Options debuggers for logon screen binaries via command-line arguments.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro (SigmaHQ), DRL 1.1
Published
2019-09-06
Updated
2026-07-30
title: Windows Suspicious Debugger Registration via Image File Execution Options
id: 32034020-d6b0-4af6-8b8a-e481fe036501
status: test
description: This rule flags process creation events whose command line includes the Image File Execution Options debugger registration path and targets common Windows logon screen binaries (e.g., sethc.exe, utilman.exe, osk.exe). Attackers use this technique to redirect the execution of trusted executables to a debugger-controlled program, enabling persistence and privilege escalation. The detection relies on process creation telemetry and string matching in the CommandLine field for both the registration path and the affected binaries.
references:
  - https://blogs.technet.microsoft.com/jonathantrull/2016/10/03/detecting-sticky-key-backdoors/
  - https://bazaar.abuse.ch/sample/6f3aa9362d72e806490a8abce245331030d1ab5ac77e400dd475748236a6cc81/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_registry_install_reg_debugger_backdoor.yml
author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule Team
date: 2019-09-06
modified: 2022-08-06
tags:
  - attack.persistence
  - attack.privilege-escalation
  - attack.t1546.008
logsource:
  category: process_creation
  product: windows
detection:
  selection1:
    CommandLine|contains: \CurrentVersion\Image File Execution Options\
  selection2:
    CommandLine|contains:
      - sethc.exe
      - utilman.exe
      - osk.exe
      - magnify.exe
      - narrator.exe
      - displayswitch.exe
      - atbroker.exe
      - HelpPane.exe
  condition: all of selection*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: ae215552-081e-44c7-805f-be16f975c8a2
    type: derived