Suspicious System Info Discovery via CurrentVersion Registry Key

Rule Info

Name
Suspicious System Info Discovery via CurrentVersion Registry Key
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to query values under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion' for system reconnaissance when initiated from a suspicious location. This key exposes a broad set of host profiling data including OS edition, build details, installation type and patch level. Attackers read these values during post-exploitation to profile the target before selecting a payload or escalation path, often executing from user-writable directories such as Temp, Downloads, or Public folders.
Date
2026-09-14 00:00:00
Modified
None
Id
607f9f95-3c5c-495d-b7bc-9919bdc77ff1
Tags
attack.discovery attack.t1082
Type
Nextron Sigma feed only (private)

Rule History