Wow6432Node Classes Autorun Keys Modification

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects modification of autostart extensibility point (ASEP) in registry.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Registry value modified" AND (OBJECTNAME contains "\Software\Wow6432Node\Classes" OR (OBJECTNAME endswith "\Software\Wow6432Node" AND OBJECTVALUENAME startswith "Classes")) AND (OBJECTNAME contains "\Folder\ShellEx\ExtShellFolderViews,\Folder\ShellEx\DragDropHandlers,\Folder\ShellEx\ColumnHandlers,\Directory\Shellex\DragDropHandlers,\Directory\Shellex\CopyHookHandlers,\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}\Instance,\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}\Instance,\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance,\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance,\AllFileSystemObjects\ShellEx\DragDropHandlers,\ShellEx\PropertySheetHandlers,\ShellEx\ContextMenuHandlers" OR (OBJECTNAME endswith "\Folder\ShellEx" AND OBJECTVALUENAME startswith "ExtShellFolderViews")) AND INFORMATION != "(Empty)" select Action1.HOSTNAME,Action1.MESSAGE,Action1.OBJECTNAME,Action1.PROCESSNAME,Action1.PREVVAL,Action1.CHANGES

Detection

Execution Mode

realtime

Log Sources

Windows

Author

Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)