{"id":"21d856f9-9281-4ded-9377-51a1a6e2a432","title":"Potential Persistence Via Logon Scripts - CommandLine","description":"Detects the addition of a new LogonScript to the registry value \"UserInitMprLogonScript\" for potential persistence","author":"Tom Ueltschi (@c_APT_ure)","status":"test","level":"high","date":"2019-01-12","modified":"2023-06-09","tags":["attack.privilege-escalation","attack.persistence","attack.t1037.001"],"technique_ids":["T1037.001"],"logsource":{"category":"process_creation","product":"windows"},"falsepositives":["Legitimate addition of Logon Scripts via the command line by administrators or third party tools"],"references":["https://cocomelonc.github.io/persistence/2022/12/09/malware-pers-20.html"],"source_path":"rules/windows/process_creation/proc_creation_win_registry_logon_script.yml","source_sha256":"79ff899ee8977cea7d9cf91a108ae552a8643cd9f4a47b49097af2ebeebf611d","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_registry_logon_script.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Potential Persistence Via Logon Scripts - CommandLine\nid: 21d856f9-9281-4ded-9377-51a1a6e2a432\nrelated:\n    - id: 0a98a10c-685d-4ab0-bddc-b6bdd1d48458\n      type: derived\nstatus: test\ndescription: Detects the addition of a new LogonScript to the registry value \"UserInitMprLogonScript\" for potential persistence\nreferences:\n    - https://cocomelonc.github.io/persistence/2022/12/09/malware-pers-20.html\nauthor: Tom Ueltschi (@c_APT_ure)\ndate: 2019-01-12\nmodified: 2023-06-09\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.t1037.001\nlogsource:\n    category: process_creation\n    product: windows\ndetection:\n    selection:\n        CommandLine|contains: 'UserInitMprLogonScript'\n    condition: selection\nfalsepositives:\n    - Legitimate addition of Logon Scripts via the command line by administrators or third party tools\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1037.001","id":"T1037.001","name":"Logon Script (Windows)","page":"techniques/enterprise/T1037.001/"}],"data_path":"data/detection-rules/21d856f9-9281-4ded-9377-51a1a6e2a432.json","kind":"sigma"}
