Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0280 — Behavior-Based Registry Modification Detection on Windows
DET0280

Behavior-Based Registry Modification Detection on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0781 Analytic 0781
Windows

Behavior chain involving abnormal registry modifications via CLI, PowerShell, WMI, or direct API calls, especially targeting persistence, privilege escalation, or defense evasion keys, potentially followed by service restart or process execution. Such as editing Notify/Userinit/Startup keys, or disabling SafeDllSearchMode.

WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=1
[RegistryKeyPathPatterns] Environment-specific list of monitored or critical registry keys, e.g., Run, Services, Security Settings, LSASS
[ParentProcessAllowList] Allowlist of legitimate registry tools (e.g., regedit.exe, msiexec.exe); used to filter known safe writes
[TimeWindow] Correlate registry change with nearby process/service execution within a defined timeframe
[SignatureCheck] Flag unsigned executables or abnormal parent-child lineage performing registry modification

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0280
STIX ID
x-mitre-detection-strategy--cf6a38ec-4c16-4c7f-8730-6e04f6dd6e67
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.