{"id":"baca5663-583c-45f9-b5dc-ea96a22ce542","title":"Sticky Key Like Backdoor Usage - Registry","description":"Detects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen","author":"Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community","status":"test","level":"critical","date":"2018-03-15","modified":"2022-11-26","tags":["attack.privilege-escalation","attack.persistence","attack.t1546.008","car.2014-11-003","car.2014-11-008"],"technique_ids":["T1546.008"],"logsource":{"category":"registry_event","product":"windows"},"falsepositives":["Unlikely"],"references":["https://blogs.technet.microsoft.com/jonathantrull/2016/10/03/detecting-sticky-key-backdoors/","https://bazaar.abuse.ch/sample/6f3aa9362d72e806490a8abce245331030d1ab5ac77e400dd475748236a6cc81/"],"source_path":"rules/windows/registry/registry_event/registry_event_stickykey_like_backdoor.yml","source_sha256":"a7f5c424d0f0a3cb039758bcec7379f7fa4dd42bd824a00f53fb96a65fed49fa","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/registry/registry_event/registry_event_stickykey_like_backdoor.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Sticky Key Like Backdoor Usage - Registry\nid: baca5663-583c-45f9-b5dc-ea96a22ce542\nstatus: test\ndescription: Detects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen\nreferences:\n    - https://blogs.technet.microsoft.com/jonathantrull/2016/10/03/detecting-sticky-key-backdoors/\n    - https://bazaar.abuse.ch/sample/6f3aa9362d72e806490a8abce245331030d1ab5ac77e400dd475748236a6cc81/\nauthor: Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community\ndate: 2018-03-15\nmodified: 2022-11-26\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.t1546.008\n    - car.2014-11-003\n    - car.2014-11-008\nlogsource:\n    category: registry_event\n    product: windows\ndetection:\n    selection_registry:\n        TargetObject|endswith:\n            - '\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\sethc.exe\\Debugger'\n            - '\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\utilman.exe\\Debugger'\n            - '\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\osk.exe\\Debugger'\n            - '\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Magnify.exe\\Debugger'\n            - '\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\Narrator.exe\\Debugger'\n            - '\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\DisplaySwitch.exe\\Debugger'\n            - '\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\atbroker.exe\\Debugger'\n            - '\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\HelpPane.exe\\Debugger'\n    condition: selection_registry\nfalsepositives:\n    - Unlikely\nlevel: critical\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1546.008","id":"T1546.008","name":"Accessibility Features","page":"techniques/enterprise/T1546.008/"}],"data_path":"data/detection-rules/baca5663-583c-45f9-b5dc-ea96a22ce542.json","kind":"sigma"}
