Detection rules › Sigma

SysKey Registry Keys Access

Status
test
Severity
high
Log source
product windows, service security
Author
Roberto Rodriguez @Cyb3rWard0g
Source
github.com/SigmaHQ/sigma

Detects handle requests and access operations to specific registry keys to calculate the SysKey

MITRE ATT&CK coverage

TacticTechniques
Discovery

Telemetry coverage

Rule body

title: SysKey Registry Keys Access
id: 9a4ff3b8-6187-4fd2-8e8b-e0eae1129495
status: test
description: Detects handle requests and access operations to specific registry keys to calculate the SysKey
references:
    - https://threathunterplaybook.com/hunts/windows/190625-RegKeyAccessSyskey/notebook.html
author: Roberto Rodriguez @Cyb3rWard0g
date: 2019-08-12
modified: 2021-11-27
tags:
    - attack.discovery
    - attack.t1012
logsource:
    product: windows
    service: security
detection:
    selection:
        EventID:
            - 4656
            - 4663
        ObjectType: 'key'
        ObjectName|endswith:
            - 'lsa\JD'
            - 'lsa\GBG'
            - 'lsa\Skew1'
            - 'lsa\Data'
    condition: selection
falsepositives:
    - Unknown
level: high

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    EventID:
        - 4656
        - 4663
    ObjectType: 'key'
    ObjectName|endswith:
        - 'lsa\JD'
        - 'lsa\GBG'
        - 'lsa\Skew1'
        - 'lsa\Data'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
ObjectNameends_with
  • lsa\Data
  • lsa\GBG
  • lsa\JD
  • lsa\Skew1
field:"ObjectName" kind:ends_with
ObjectTypeeq
  • key corpus 5 (sigma 5)
field:"ObjectType" kind:eq value:"key"