Path To Screensaver Binary Modified
Last updated on:
Applies to: Log360Log360 Cloud
In this page
About the rule
Rule Type
Standard
Rule Description
Detects value modification of registry key containing path to binary used as screensaver.
Severity
Trouble
Rule Requirement
Criteria
Action1:
actionname = "Registry Event" AND (OBJECTNAME endswith "\Control Panel\Desktop\SCRNSAVE.EXE" OR (OBJECTNAME endswith "\Control Panel\Desktop" AND OBJECTVALUENAME = "SCRNSAVE.EXE")) AND PROCESSNAME notendswith "\rundll32.exe,\explorer.exe"
select Action1.HOSTNAME,Action1.MESSAGE,Action1.PROCESSNAME,Action1.OBJECTNAME,Action1.OBJECTVALUENAME,Action1.ACCESSES,Action1.USERNAME,Action1.DOMAIN,Action1.PREVVAL,Action1.CHANGES,Action1.INFORMATION
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Bartlomiej Czyz @bczyz1, oscd.community


