Rule Info
Name
Potential RID Hijacking Attempt - Registry
Author
Swachchhanda Shrawn Poudel (Nextron Systems)
Description
Detects modifications to the RID Set registry keys which could indicate an attempt to perform RID hijacking attacks.
In RID hijacking, an attacker modifies the RID set of a user account like guest user to escalate privileges or impersonate another user.
Date
2026-05-19 00:00:00
Modified
None
Id
82d9e746-72be-4952-8d59-6c2b7e801d8f
Tags
attack.persistence attack.privilege-escalation attack.t1098
Type
Nextron Sigma feed only (private)
