Keyboard Layout - Scancode Map Modification - CommandLine

Rule Info

Name
Keyboard Layout - Scancode Map Modification - CommandLine
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects setting of the "Scancode Map" registry value via command line. This value allow a user to customize and map keyboard keys to different values. Ransomware was seen using this technique in order to prevent user from interacting with the machine during the encryption process.
Date
2024-05-03 00:00:00
Modified
None
Id
28573f97-f43e-460e-902c-c15beb30d575
Tags
attack.execution
Type
Nextron Sigma feed only (private)

Rule History