AN0871
Analytic 0871
Windows
Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login.
WinEventLog:Security
EventCode=4672
WinEventLog:Security
EventCode=4688
WinEventLog:Sysmon
EventCode=13, 14
WinEventLog:Sysmon
EventCode=12
[TimeWindow]
Correlate registry change and process execution within a specific user logon session (e.g., 5–10 minutes)
[ParentProcessName]
Expected parent processes for Active Setup launched binaries (e.g., explorer.exe). Deviations may indicate abuse.
[StubPathValueEntropy]
Degree of randomness/uncommonness in StubPath values. High entropy may indicate obfuscation.
[SignedBinaryStatus]
Flag if launched binary in StubPath is unsigned or uncommon for baseline
[RegistryKeyOwner]
Check which user/context added the Active Setup key to detect privilege abuse