Detection rules › Elastic

Sensitive Hive Access via Registry Backup

Source
github.com/elastic/protections-artifacts

Identifies access attempts to sensitive registry hives like the Security Account Manager (SAM) database file from the registry backdup folder. Adversaries may use this option to evade detections looking for registry hive direct access.

MITRE ATT&CK coverage

Rule body

[rule]
description = """
Identifies access attempts to sensitive registry hives like the Security Account Manager (SAM) database file from the
registry backdup folder. Adversaries may use this option to evade detections looking for registry hive direct access.
"""
id = "87a465e3-b8a2-4df7-9590-86782aa0546c"
license = "Elastic License v2"
name = "Sensitive Hive Access via Registry Backup"
os_list = ["windows"]
version = "1.0.3"

query = '''
file where event.action == "open" and event.outcome == "success" and
 file.path :
      ("?:\\Windows\\System32\\config\\RegBack\\SAM",
       "?:\\Windows\\System32\\config\\RegBack\\SECURITY",
       "?:\\Windows\\System32\\config\\RegBack\\SYSTEM") and
 user.id != null and process.executable : "?:\\*" and process.pid != 4 and
 not process.executable :
             ("?:\\Windows\\System32\\svchost.exe",
              "?:\\Program Files (x86)\\*",
              "?:\\Program Files\\*",
              "?:\\Windows\\System32\\wuauclt.exe",
              "?:\\$WINDOWS.~BT\\Sources\\SetupHost.exe",
              "?:\\Windows\\System32\\vmwp.exe",
              "?:\\Windows\\System32\\Dism.exe",
              "?:\\Windows\\System32\\wbengine.exe",
              "?:\\Windows\\System32\\mmc.exe",
              "?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
              "?:\\Windows\\System32\\sppsvc.exe",
              "?:\\Windows\\System32\\backgroundTaskHost.exe",
              "?:\\Windows\\System32\\lsass.exe",
              "?:\\Windows\\System32\\taskhostw.exe",
              "?:\\Windows\\System32\\taskhost.exe",
              "?:\\Windows\\System32\\SearchProtocolHost.exe",
              "?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
              "?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*.exe",
              "?:\\Program Files\\Windows Defender Advanced Threat Protection\\*.exe",
              "?:\\Program Files\\Microsoft Monitoring Agent\\Agent\\*.exe",
              "?:\\Windows\\System32\\SrTasks.exe",
              "?:\\Windows\\System32\\rstrui.exe",
              "?:\\Windows\\System32\\MRT.exe",
              "?:\\Windows\\System32\\conhost.exe") and

 not (process.code_signature.trusted == true and
      process.code_signature.subject_name :
         ("ESET, spol. s r.o.", "Commvault Systems, Inc.", "Eric R. Zimmerman", "EFOLDER, INC.", "Absolute Software Corp.",
          "Refraction Point, Inc"))
'''

min_endpoint_version = "8.0.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1003"
name = "OS Credential Dumping"
reference = "https://attack.mitre.org/techniques/T1003/"
[[threat.technique.subtechnique]]
id = "T1003.002"
name = "Security Account Manager"
reference = "https://attack.mitre.org/techniques/T1003/002/"



[threat.tactic]
id = "TA0006"
name = "Credential Access"
reference = "https://attack.mitre.org/tactics/TA0006/"

[internal]
min_endpoint_version = "8.0.0"

Stages and Predicates

Stage 1: file

file where event.action == "open" and event.outcome == "success" and
 file.path :
      ("?:\\Windows\\System32\\config\\RegBack\\SAM",
       "?:\\Windows\\System32\\config\\RegBack\\SECURITY",
       "?:\\Windows\\System32\\config\\RegBack\\SYSTEM") and
 user.id != null and process.executable : "?:\\*" and process.pid != 4 and
 not process.executable :
             ("?:\\Windows\\System32\\svchost.exe",
              "?:\\Program Files (x86)\\*",
              "?:\\Program Files\\*",
              "?:\\Windows\\System32\\wuauclt.exe",
              "?:\\$WINDOWS.~BT\\Sources\\SetupHost.exe",
              "?:\\Windows\\System32\\vmwp.exe",
              "?:\\Windows\\System32\\Dism.exe",
              "?:\\Windows\\System32\\wbengine.exe",
              "?:\\Windows\\System32\\mmc.exe",
              "?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
              "?:\\Windows\\System32\\sppsvc.exe",
              "?:\\Windows\\System32\\backgroundTaskHost.exe",
              "?:\\Windows\\System32\\lsass.exe",
              "?:\\Windows\\System32\\taskhostw.exe",
              "?:\\Windows\\System32\\taskhost.exe",
              "?:\\Windows\\System32\\SearchProtocolHost.exe",
              "?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
              "?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*.exe",
              "?:\\Program Files\\Windows Defender Advanced Threat Protection\\*.exe",
              "?:\\Program Files\\Microsoft Monitoring Agent\\Agent\\*.exe",
              "?:\\Windows\\System32\\SrTasks.exe",
              "?:\\Windows\\System32\\rstrui.exe",
              "?:\\Windows\\System32\\MRT.exe",
              "?:\\Windows\\System32\\conhost.exe") and

 not (process.code_signature.trusted == true and
      process.code_signature.subject_name :
         ("ESET, spol. s r.o.", "Commvault Systems, Inc.", "Eric R. Zimmerman", "EFOLDER, INC.", "Absolute Software Corp.",
          "Refraction Point, Inc"))

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
process.code_signature.subject_nameeqESET, spol. s r.o., Commvault Systems, Inc., Eric R. Zimmerman, EFOLDER, INC., Absolute Software Corp., Refraction Point, Incexcludes:process.code_signature.subject_name
process.code_signature.trustedeqtrueexcludes:process.code_signature.trusted field:"process.code_signature.trusted" value:"true"
process.executablewildcard?:\Windows\System32\svchost.exe, ?:\Program Files (x86)\*, ?:\Program Files\*, ?:\Windows\System32\wuauclt.exe, ?:\$WINDOWS.~BT\Sources\SetupHost.exe, ?:\Windows\System32\vmwp.exe, ?:\Windows\System32\Dism.exe, ?:\Windows\System32\wbengine.exe, ?:\Windows\System32\mmc.exe, ?:\ProgramData\Microsoft\Windows Defender\Platform\*.exe, ?:\Windows\System32\sppsvc.exe, ?:\Windows\System32\backgroundTaskHost.exe, ?:\Windows\System32\lsass.exe, ?:\Windows\System32\taskhostw.exe, ?:\Windows\System32\taskhost.exe, ?:\Windows\System32\SearchProtocolHost.exe, ?:\ProgramData\Microsoft\Windows Defender\Platform\*.exe, ?:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*.exe, ?:\Program Files\Windows Defender Advanced Threat Protection\*.exe, ?:\Program Files\Microsoft Monitoring Agent\Agent\*.exe, ?:\Windows\System32\SrTasks.exe, ?:\Windows\System32\rstrui.exe, ?:\Windows\System32\MRT.exe, ?:\Windows\System32\conhost.exeexcludes:process.executable

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
event.actioneq
  • open corpus 52 (elastic 51, sigma 1)
field:"EventType" kind:eq value:"open"
event.outcomeeq
  • success corpus 369 (elastic 369)
field:"event.outcome" kind:eq value:"success"
file.pathwildcard
  • ?:\Windows\System32\config\RegBack\SAM corpus 2 (elastic 2)
  • ?:\Windows\System32\config\RegBack\SECURITY corpus 2 (elastic 2)
  • ?:\Windows\System32\config\RegBack\SYSTEM corpus 2 (elastic 2)
field:"TargetFilename" kind:wildcard
process.executablewildcard
  • ?:\* corpus 18 (elastic 18)
field:"Image" kind:wildcard value:"?:\*"
process.pidne
  • 4 transforms: number corpus 44 (elastic 44)
field:"process_id" kind:ne value:"4"
user.idis_not_null
  • (no value, null check)
field:"user.id" kind:is_not_null