AN0341
Analytic 0341
Windows
Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence.
WinEventLog:Sysmon
EventCode=13, 14
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=7
WinEventLog:Sysmon
EventCode=1
[RegistryPathScope]
May need to be tuned to only monitor `W32Time\TimeProviders` subkey path for performance optimization
[UserContext]
Should focus on activity from administrative or SYSTEM accounts
[TimeWindow]
Controls correlation window between registry modification and DLL drop
[DllPathEntropyThreshold]
Used for anomaly scoring on DLL path patterns (e.g., random names or temp directories)