Windows Suspicious Run Key Created from Downloads or Outlook/IE Temporary Folders

Alerts on registry Run key writes originating from Downloads or temporary Outlook/IE directories on Windows.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_event
Author
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poude (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-10-01
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags registry Run key creations where the writing process image path contains common user download and temporary Outlook or Internet Explorer directories. Attackers abuse Run and policy Run keys to establish persistence by launching code at user logon. It relies on Windows registry event telemetry, matching both the process image path substrings and the TargetObject paths for Run locations, including 64-bit, WOW6432Node, and Explorer policy Run keys.

Related detections9 linkedT1547.001 — drag to rearrange
Suspicious Autorun Registry Persistence via sausageLoop Run Key
Malicious BabyLockerKZ Run Key Persistence
Suspicious Run Key Persistence Pointing To User-Writable Path
Malicious Ctrlpanel Run Key Autostart Persistence (via registry_set)
Persistence Run Key Pointing to svchost.exe in AppData Roaming
URL Shortcut File Created in Startup Folder for Persistence
Suspicious Run Key Persistence via UpdateCheck Value in Operation TrueChaos
Suspicious Run Key Persistence Pointing to AppData Local Copy
Malicious WezRat Persistence via Chrome Updater Run Key
Windows Suspicious Run Key Created from Downloads or Outlook/IE Temporary Folders
Pivot detection · T1547.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.