UC-L3-022
Registry Run Key Modification
Sysmon Event ID 13
Use case development / Detect Malware Infections / Detect Persistence Mechanisms
sigma
Detection rule
title: Registry Run Key Persistence
status: experimental
description: Detects modification of registry run keys for persistence
logsource:
product: windows
category: registry_event
detection:
selection:
EventType: SetValue
TargetObject|contains:
- '\Software\Microsoft\Windows\CurrentVersion\Run'
- '\Software\Microsoft\Windows\CurrentVersion\RunOnce'
condition: selection
falsepositives:
- Legitimate software installation
level: medium
tags:
- attack.persistence
- attack.t1547.001Test cases
- Add value to Run registry key
False positive guidance
Whitelist known legitimate software installations.