Rule Info
Name
Keyboard Layout - Scancode Map Modification - Registry
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects setting of the "Scancode Map" registry value.
This value allow a user to customize and map keyboard keys to different values.
Ransomware was seen using this technique in order to prevent user from interacting with the machine during the encryption process.
Reference
Date
2024-05-07 00:00:00
Modified
None
Id
f4c9d001-1d2c-4fc2-a39f-29c80922f388
Tags
attack.defense-evasion
Type
Nextron Sigma feed only (private)