Detectionhightest

Exports Registry Key To an Alternate Data Stream

Exports the target Registry key and hides it in the specified alternate data stream.

Convert In Phoenix Studio

Open this Sigma rule in the converter with the YAML preloaded and ready for backend selection.

Launch
Oddvar Moe, Sander Wiebing, oscd.communityCreated Wed Oct 07Updated Sat Nov 270d7a9363-af70-4e7b-a3b7-1a176b7fbe84windows
Log Source
WindowsAlternate Data Stream
ProductWindows← raw: windows
CategoryAlternate Data Stream← raw: create_stream_hash
Detection Logic
Detection Logic1 selector
detection:
    selection:
        Image|endswith: '\regedit.exe'
    condition: selection
False Positives
Unknown

False positive likelihood has not been assessed. Additional context may be needed during triage.

Rule Metadata
Rule ID
0d7a9363-af70-4e7b-a3b7-1a176b7fbe84
Status
test
Level
high
Type
Detection
Created
Wed Oct 07
Modified
Sat Nov 27
Path
rules/windows/create_stream_hash/create_stream_hash_regedit_export_to_ads.yml
Raw Tags
attack.defense-evasionattack.t1564.004
View on GitHub