1200KM / detection
T1546.002 Screensaver — Detection Rules
Detection workspace for T1546.002 Screensaver: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious Screensaver Binary File Creation · test · medium · {"product":"windows","category":"file_event"}
- Writing Local Admin Share · test · medium · {"product":"windows","category":"file_event"}
- Suspicious ScreenSave Change by Reg.exe · test · medium · {"category":"process_creation","product":"windows"}
- Path To Screensaver Binary Modified · test · medium · {"category":"registry_event","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0154 Detect Screensaver-Based Persistence via Registry and Execution Chains
AN0441 Analytic 0441
Unusual screensaver (.scr) executions correlated with recent registry modifications to HKCU\Control Panel\Desktop values such as SCRNSAVE.exe, ScreenSaveTimeout, and ScreenSaveActive. Detection focuses on PE image paths not consistent with known legitimate screensavers and triggered after user inactivity timeout.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1546.002 simulation workspace
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.