RemoteRegistry Service Started Via Svchost

Rule Info

Name
RemoteRegistry Service Started Via Svchost
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the start of the "RemoteRegistry" service by looking at "svchost" process creation events. If not authorized this action can indicate a potential lateral movement activity being in-progress, as the "Remote Registry" service enables remote users to modify registry settings on a computer. Attackers can leverage this in order to manipulate certain value remotely.
Date
2024-07-10 00:00:00
Modified
None
Id
1f892c02-3dac-4a1c-8b08-16b9ec28664c
Tags
attack.defense-evasion attack.t1218
Type
Nextron Sigma feed only (private)

Rule History