Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0061 — Detect Default File Association Hijack via Registry & Execution Correlation on Windows
DET0061

Detect Default File Association Hijack via Registry & Execution Correlation on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0170 Analytic 0170
Windows

Detects modification of registry keys used for default file handlers, followed by anomalous process execution from user-initiated file opens. This includes tracking changes under HKCU and HKCR for file extension mappings, and correlating them with new or suspicious handler paths launching unusual child processes (e.g., PowerShell, cmd, wscript).

WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=1 WinEventLog:Security EventCode=4672
[TimeWindow] Defines how long after the registry modification to correlate a suspicious process execution
[UserContext] Tune to ignore known admin or installer behavior in specific user profiles
[SuspiciousHandlerPathRegex] Pattern match for suspicious handler paths (e.g., powershell.exe, rundll32.exe)

Detected Techniques

1

Details

MITRE ID
DET0061
STIX ID
x-mitre-detection-strategy--61585647-dcc0-4c46-9333-c59796997826
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.