Suspicious Autorun Registry Modified via WMI

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects suspicious activity where the WMIC process is used to create an autorun registry entry via reg.exe, which is often indicative of persistence mechanisms employed by malware.

Severity

Critical

Rule Requirement

Criteria

Action1: actionname = "Process started" AND (( PROCESSNAME endswith "\wmic.exe" OR ORIGINALFILENAME = "wmic.exe" OR PARENTPROCESSNAME endswith "\wmiprvse.exe" ) AND ( COMMANDLINE contains "reg" AND COMMANDLINE contains "add" AND COMMANDLINE contains "\Microsoft\Windows\CurrentVersion\Run,\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" )) AND (( COMMANDLINE contains ":\Perflogs,:\ProgramData,:\Windows\Temp,:\Temp,\AppData\Local\Temp,\AppData\Roaming,:\$Recycle.bin,:\Users\Default,:\Users\public,%temp%,%tmp%,%Public%,%AppData%" ) OR ( COMMANDLINE contains ":\Users" AND COMMANDLINE = "\Favorites,\Favourites,\Contacts,\Music,\Pictures,\Documents,\Photos" )) select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME,Action1.DOMAIN,Action1.ORIGINALFILENAME,Action1.PARENTPROCESSID,Action1.PROCESSID,Action1.PRODUCT_NAME,Action1.SECURITYID

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Swachchhanda Shrawan Poudel (Nextron Systems)