AllowedProcessName Registry Value Modification

Rule Info

Name
AllowedProcessName Registry Value Modification
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects modification of an `AllowedProcessName` registry value under any Windows service key. Some kernel drivers and privileged services use registry-configured process paths to determine which applications are permitted to access sensitive functionality. An attacker with registry write access may modify this value to reference an attacker-controlled executable, causing the associated component to treat the malicious process as trusted. Successful abuse could grant access to privileged operations exposed by the component, such as reading protected process memory, terminating processes, or interfering with security software.
Date
2026-07-15 00:00:00
Modified
None
Id
7f8f6ae7-4f9b-49e4-8149-93c308c0c2b5
Tags
attack.credential-access attack.defense-impairment attack.persistence attack.t1003.001 attack.t1112
Type
Nextron Sigma feed only (private)

Rule History