Rule Info
Name
AllowedProcessName Registry Value Modification
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects modification of an `AllowedProcessName` registry value under any Windows service key.
Some kernel drivers and privileged services use registry-configured process paths to determine
which applications are permitted to access sensitive functionality. An attacker with registry
write access may modify this value to reference an attacker-controlled executable, causing the
associated component to treat the malicious process as trusted.
Successful abuse could grant access to privileged operations exposed by the component, such as
reading protected process memory, terminating processes, or interfering with security software.
Date
2026-07-15 00:00:00
Modified
None
Id
7f8f6ae7-4f9b-49e4-8149-93c308c0c2b5
Tags
attack.credential-access attack.defense-impairment attack.persistence attack.t1003.001 attack.t1112
Type
Nextron Sigma feed only (private)
