{"id":"20f0ee37-5942-4e45-b7d5-c5b5db9df5cd","title":"CurrentVersion Autorun Keys Modification","description":"Detects modification of autostart extensibility point (ASEP) in registry.","author":"Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)","status":"test","level":"medium","date":"2019-10-25","modified":"2025-10-22","tags":["attack.privilege-escalation","attack.persistence","attack.t1547.001"],"technique_ids":["T1547.001"],"logsource":{"category":"registry_set","product":"windows"},"falsepositives":["Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason","Legitimate administrator sets up autorun keys for legitimate reason"],"references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md","https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns","https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d","https://oddvar.moe/2018/03/21/persistence-using-runonceex-hidden-from-autoruns-exe/"],"source_path":"rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_currentversion.yml","source_sha256":"78684f006cf1dbfea9962f0fd64dd3b1e32e8b09029719fb882392fb89ab49d7","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_currentversion.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: CurrentVersion Autorun Keys Modification\nid: 20f0ee37-5942-4e45-b7d5-c5b5db9df5cd\nrelated:\n    - id: 17f878b8-9968-4578-b814-c4217fc5768c\n      type: obsolete\nstatus: test\ndescription: Detects modification of autostart extensibility point (ASEP) in registry.\nreferences:\n    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.001/T1547.001.md\n    - https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns\n    - https://gist.github.com/GlebSukhodolskiy/0fc5fa5f482903064b448890db1eaf9d # a list with registry keys\n    - https://oddvar.moe/2018/03/21/persistence-using-runonceex-hidden-from-autoruns-exe/\nauthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)\ndate: 2019-10-25\nmodified: 2025-10-22\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.t1547.001\nlogsource:\n    category: registry_set\n    product: windows\ndetection:\n    selection_current_version_base:\n        TargetObject|contains: '\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion'\n    selection_current_version_keys:\n        TargetObject|contains:\n            - '\\ShellServiceObjectDelayLoad'\n            - '\\Run\\'\n            - '\\RunOnce\\'\n            - '\\RunOnceEx\\'\n            - '\\RunServices\\'\n            - '\\RunServicesOnce\\'\n            - '\\Policies\\System\\Shell'\n            - '\\Policies\\Explorer\\Run'\n            - '\\Group Policy\\Scripts\\Startup'\n            - '\\Group Policy\\Scripts\\Shutdown'\n            - '\\Group Policy\\Scripts\\Logon'\n            - '\\Group Policy\\Scripts\\Logoff'\n            - '\\Explorer\\ShellServiceObjects'\n            - '\\Explorer\\ShellIconOverlayIdentifiers'\n            - '\\Explorer\\ShellExecuteHooks'\n            - '\\Explorer\\SharedTaskScheduler'\n            - '\\Explorer\\Browser Helper Objects'\n            - '\\Authentication\\PLAP Providers'\n            - '\\Authentication\\Credential Providers'\n            - '\\Authentication\\Credential Provider Filters'\n    filter_main_generic_all:\n        - Details: '(Empty)'\n        - TargetObject|endswith: '\\NgcFirst\\ConsecutiveSwitchCount'\n        - Image|endswith:\n              - '\\AppData\\Local\\Microsoft\\OneDrive\\Update\\OneDriveSetup.exe' # C:\\Users\\*\\AppData\\Local\\Microsoft\\OneDrive\\Update\\OneDriveSetup.exe\n              - '\\AppData\\Roaming\\Spotify\\Spotify.exe'\n              - '\\AppData\\Local\\WebEx\\WebexHost.exe'\n        - Image:\n              - 'C:\\WINDOWS\\system32\\devicecensus.exe'\n              - 'C:\\Windows\\system32\\winsat.exe'\n              - 'C:\\Program Files\\Microsoft OneDrive\\StandaloneUpdater\\OneDriveSetup.exe'\n              - 'C:\\Program Files (x86)\\Microsoft OneDrive\\StandaloneUpdater\\OneDriveSetup.exe'\n              - 'C:\\Program Files\\Microsoft OneDrive\\Update\\OneDriveSetup.exe'\n              - 'C:\\Program Files (x86)\\Microsoft OneDrive\\Update\\OneDriveSetup.exe'\n              - 'C:\\Program Files\\Microsoft Office\\root\\integration\\Addons\\OneDriveSetup.exe'\n              - 'C:\\Program Files (x86)\\Microsoft Office\\root\\integration\\Addons\\OneDriveSetup.exe'\n              - 'C:\\Program Files\\KeePass Password Safe 2\\ShInstUtil.exe'\n              - 'C:\\Program Files\\Everything\\Everything.exe'\n              - 'C:\\Program Files (x86)\\Microsoft Office\\root\\integration\\integrator.exe'\n              - 'C:\\Program Files\\Microsoft Office\\root\\integration\\integrator.exe'\n    filter_main_null:\n        Details: null\n    filter_main_logonui:\n        Image: 'C:\\Windows\\system32\\LogonUI.exe'\n        TargetObject|contains:\n            - '\\Authentication\\Credential Providers\\{D6886603-9D2F-4EB2-B667-1971041FA96B}\\'  # PIN\n            - '\\Authentication\\Credential Providers\\{BEC09223-B018-416D-A0AC-523971B639F5}\\'  # fingerprint\n            - '\\Authentication\\Credential Providers\\{8AF662BF-65A0-4D0A-A540-A338A999D36F}\\'  # facial recognizion\n            - '\\Authentication\\Credential Providers\\{27FBDB57-B613-4AF2-9D7E-4FA7A66C21AD}\\'  # Trusted Signal (Phone proximity, Network location)\n    filter_main_edge:\n        Image|startswith:\n            - 'C:\\Program Files (x86)\\Microsoft\\EdgeUpdate\\Install\\'\n            - 'C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\'\n            - 'C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe'\n    filter_main_defender:\n        Image: 'C:\\Program Files\\Windows Defender\\MsMpEng.exe'\n    filter_main_teams:\n        Image|endswith: '\\Microsoft\\Teams\\current\\Teams.exe'\n        Details|contains: '\\Microsoft\\Teams\\Update.exe --processStart '\n    filter_main_ctfmon:\n        Image: 'C:\\Windows\\system32\\userinit.exe'\n        Details: 'ctfmon.exe /n'\n    filter_optional_dropbox:\n        Image: 'C:\\Windows\\system32\\regsvr32.exe'\n        TargetObject|contains: 'DropboxExt'\n        Details|endswith: 'A251-47B7-93E1-CDD82E34AF8B}'\n    filter_optional_opera_1:\n        TargetObject|endswith: '\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\Opera Browser Assistant'\n        Details: 'C:\\Program Files\\Opera\\assistant\\browser_assistant.exe'\n    filter_optional_opera_2:\n        TargetObject|endswith: '\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Opera Stable'\n        Details:\n            - 'C:\\Program Files\\Opera\\launcher.exe'\n            - 'C:\\Program Files (x86)\\Opera\\launcher.exe'\n    filter_optional_itunes:\n        TargetObject|endswith: '\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\iTunesHelper'\n        Details: '\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"'\n    filter_optional_zoom:\n        TargetObject|endswith: '\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\zoommsirepair'\n        Details: '\"C:\\Program Files\\Zoom\\bin\\installer.exe\" /repair'\n    filter_optional_greenshot:\n        TargetObject|endswith: '\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\Greenshot'\n        Details: 'C:\\Program Files\\Greenshot\\Greenshot.exe'\n    filter_optional_googledrive1:\n        TargetObject|endswith: '\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\GoogleDriveFS'\n        Details|startswith: 'C:\\Program Files\\Google\\Drive File Stream\\'\n        Details|contains: '\\GoogleDriveFS.exe'\n    filter_optional_googledrive2:\n        TargetObject|contains: 'GoogleDrive'\n        Details:\n            - '{CFE8B367-77A7-41D7-9C90-75D16D7DC6B6}'\n            - '{A8E52322-8734-481D-A7E2-27B309EF8D56}'\n            - '{C973DA94-CBDF-4E77-81D1-E5B794FBD146}'\n            - '{51EF1569-67EE-4AD6-9646-E726C3FFC8A2}'\n    filter_optional_onedrive:\n        Details|startswith:\n            - 'C:\\Windows\\system32\\cmd.exe /q /c rmdir /s /q \"C:\\Users\\'\n            - 'C:\\Windows\\system32\\cmd.exe /q /c del /q \"C:\\Users\\'\n        Details|contains: '\\AppData\\Local\\Microsoft\\OneDrive\\'\n    filter_optional_python:\n        TargetObject|contains: '\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\{'\n        Details|contains|all:\n            - '\\AppData\\Local\\Package Cache\\{'\n            - '}\\python-'\n        Details|endswith: '.exe\" /burn.runonce'\n    filter_optional_officeclicktorun:\n        Image|startswith:\n            - 'C:\\Program Files\\Common Files\\Microsoft Shared\\ClickToRun\\'\n            - 'C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\ClickToRun\\'\n        Image|endswith: '\\OfficeClickToRun.exe'\n    filter_optional_teams:\n        Image|endswith: '\\Microsoft\\Teams\\current\\Teams.exe'\n        Details|contains: '\\Microsoft\\Teams\\Update.exe --processStart'\n    filter_optional_AVG_setup:\n        Image|contains:\n            - 'C:\\Program Files\\AVG\\Antivirus\\Setup\\'\n            - 'C:\\Program Files (x86)\\AVG\\Antivirus\\Setup\\'\n            - '\\instup.exe'\n        Details:\n            - '\"C:\\Program Files\\AVG\\Antivirus\\AvLaunch.exe\" /gui'\n            - '\"C:\\Program Files (x86)\\AVG\\Antivirus\\AvLaunch.exe\" /gui'\n            - '{472083B0-C522-11CF-8763-00608CC02F24}'\n            - '{472083B1-C522-11CF-8763-00608CC02F24}'\n    filter_optional_Avast:\n        Image|contains:\n            - 'C:\\Program Files\\Avast Software\\Avast\\Setup\\'\n            - 'C:\\Program Files (x86)\\Avast Software\\Avast\\Setup\\'\n            - '\\instup.exe'\n        Details:\n            - '\"C:\\Program Files\\Avast Software\\Avast\\AvLaunch.exe\" /gui'\n            - '\"C:\\Program Files (x86)\\Avast Software\\Avast\\AvLaunch.exe\" /gui'\n    filter_optional_AVG_avgtoolsvc:\n        Image:\n            - 'C:\\Program Files\\AVG\\Antivirus\\avgToolsSvc.exe'\n            - 'C:\\Program Files (x86)\\AVG\\Antivirus\\avgToolsSvc.exe'\n        TargetObject|contains: '\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartupApproved\\Run\\'\n        Details: 'Binary Data'\n    filter_optional_aurora_dashboard:\n        Image|endswith:\n            - '\\aurora-agent-64.exe'\n            - '\\aurora-agent.exe'\n        TargetObject|endswith: '\\Microsoft\\Windows\\CurrentVersion\\Run\\aurora-dashboard'\n        Details: 'C:\\Program Files\\Aurora-Agent\\tools\\aurora-dashboard.exe'\n    filter_optional_everything:\n        TargetObject|endswith: '\\Microsoft\\Windows\\CurrentVersion\\Run\\Everything'\n        Details|endswith: '\\Everything\\Everything.exe\" -startup' # We remove the starting part as it could be installed in different locations\n    filter_optional_discord:\n        TargetObject|endswith: '\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Discord'\n        Details|endswith: '\\Discord\\Update.exe --processStart Discord.exe'\n    condition: all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*\nfalsepositives:\n    - Legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason\n    - Legitimate administrator sets up autorun keys for legitimate reason\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1547.001","id":"T1547.001","name":"Registry Run Keys / Startup Folder","page":"techniques/enterprise/T1547.001/"}],"data_path":"data/detection-rules/20f0ee37-5942-4e45-b7d5-c5b5db9df5cd.json","kind":"sigma"}
