Registry Modification Attempt Via VBScript - PowerShell

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects PowerShell invoking VBScript-style CreateObject/RegWrite to modify registry entries.

Severity

Trouble

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Swachchhanda Shrawan Poudel (Nextron Systems)