1200KM / sigma-rule
Potential Suspicious Activity Using SeCEdit — Sigma Rule
Sigma rule c2c76b77-32be-4d1f-82c9-7e544bdfe0eb. Potential Suspicious Activity Using SeCEdit — Sigma Rule. Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy
Rule metadata and linked tags
Author: Janantha Marasinghe. Source status: test; severity: medium. Source dates: 2022-11-18 / 2022-12-30.
{
"category": "process_creation",
"product": "windows"
}Pinned original Sigma rule · Detection Rule License 1.1
Source SHA-256: cfc1d16a16bb249a4ac0692a303e6385fec1d486c7457b2ef8b09665fd5fc718
Detection logic
Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.
title: Potential Suspicious Activity Using SeCEdit
id: c2c76b77-32be-4d1f-82c9-7e544bdfe0eb
status: test
description: Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy
references:
- https://blueteamops.medium.com/secedit-and-i-know-it-595056dee53d
- https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/secedit
author: Janantha Marasinghe
date: 2022-11-18
modified: 2022-12-30
tags:
- attack.collection
- attack.discovery
- attack.persistence
- attack.credential-access
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.defense-impairment
- attack.t1685.001
- attack.t1547.001
- attack.t1505.005
- attack.t1556.002
- attack.t1685
- attack.t1574.007
- attack.t1564.002
- attack.t1546.008
- attack.t1546.007
- attack.t1547.014
- attack.t1547.010
- attack.t1547.002
- attack.t1557
- attack.t1082
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: '\secedit.exe'
- OriginalFileName: 'SeCEdit'
selection_flags_discovery:
CommandLine|contains|all:
- '/export'
- '/cfg'
selection_flags_configure:
CommandLine|contains|all:
- '/configure'
- '/db'
# filter:
# SubjectUserName|endswith: '$' SubjectUserName is from event ID 4719 in the Windows Security log
condition: selection_img and (1 of selection_flags_*)
falsepositives:
- Legitimate administrative use
level: medium
False positives
- Legitimate administrative use
Source references
Connected ecosystem references
Exact source-tagged techniques
- T1082 · System Information Discovery · Detection rules & anomalies
- T1505.005 · Terminal Services DLL · Detection rules & anomalies
- T1546.007 · Netsh Helper DLL · Detection rules & anomalies
- T1546.008 · Accessibility Features · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1547.002 · Authentication Package · Detection rules & anomalies
- T1547.010 · Port Monitors · Detection rules & anomalies
- T1547.014 · Active Setup · Detection rules & anomalies
- T1556.002 · Password Filter DLL · Detection rules & anomalies
- T1557 · Adversary-in-the-Middle · Detection rules & anomalies
- T1564.002 · Hidden Users · Detection rules & anomalies
- T1574.007 · Path Interception by PATH Environment Variable · Detection rules & anomalies
- T1685 · Disable or Modify Tools · Detection rules & anomalies
- T1685.001 · Disable or Modify Windows Event Log · Detection rules & anomalies
Telemetry review
Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.