Detectionhightest
Exports Registry Key To an Alternate Data Stream
Exports the target Registry key and hides it in the specified alternate data stream.
Convert In Phoenix Studio
Open this Sigma rule in the converter with the YAML preloaded and ready for backend selection.
Launch
Oddvar Moe, Sander Wiebing, oscd.communityCreated Wed Oct 07Updated Sat Nov 270d7a9363-af70-4e7b-a3b7-1a176b7fbe84windows
Log Source
WindowsAlternate Data Stream
ProductWindows← raw: windows
CategoryAlternate Data Stream← raw: create_stream_hash
Detection Logic
Detection Logic1 selector
detection:
selection:
Image|endswith: '\regedit.exe'
condition: selectionFalse Positives
Unknown
False positive likelihood has not been assessed. Additional context may be needed during triage.
MITRE ATT&CK
Tactics
Sub-techniques
Rule Metadata
Rule ID
0d7a9363-af70-4e7b-a3b7-1a176b7fbe84
Status
test
Level
high
Type
Detection
Created
Wed Oct 07
Modified
Sat Nov 27
Author
Path
rules/windows/create_stream_hash/create_stream_hash_regedit_export_to_ads.yml
Raw Tags
attack.defense-evasionattack.t1564.004