User Shell Folders Registry Modification via CommandLine

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects modifications to User Shell Folders registry values via reg.exe or PowerShell, which could indicate persistence attempts.

Severity

Trouble

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Swachchhanda Shrawan Poudel (Nextron Systems)