Rule Info
Name
Suspicious System Info Discovery via CurrentVersion Registry Key
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to query values under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
for system reconnaissance when initiated from a suspicious location. This key exposes a
broad set of host profiling data including OS edition, build details, installation type
and patch level. Attackers read these values during post-exploitation to profile the target
before selecting a payload or escalation path, often executing from user-writable directories
such as Temp, Downloads, or Public folders.
Reference
Date
2026-09-14 00:00:00
Modified
None
Id
607f9f95-3c5c-495d-b7bc-9919bdc77ff1
Tags
attack.discovery attack.t1082
Type
Nextron Sigma feed only (private)
