Atbroker Registry Change
Detects creation/modification of Assistive Technology applications and persistence with usage of 'at'
Sigma rule (View on GitHub)
1title: Atbroker Registry Change
2id: 9577edbb-851f-4243-8c91-1d5b50c1a39b
3status: test
4description: Detects creation/modification of Assistive Technology applications and persistence with usage of 'at'
5references:
6 - http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/
7 - https://lolbas-project.github.io/lolbas/Binaries/Atbroker/
8author: Mateusz Wydra, oscd.community
9date: 2020-10-13
10modified: 2023-01-19
11tags:
12 - attack.defense-evasion
13 - attack.t1218
14 - attack.persistence
15 - attack.t1547
16logsource:
17 category: registry_event
18 product: windows
19detection:
20 selection:
21 TargetObject|contains:
22 - 'Software\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs'
23 - 'Software\Microsoft\Windows NT\CurrentVersion\Accessibility\Configuration'
24 filter_atbroker:
25 Image: 'C:\Windows\system32\atbroker.exe'
26 TargetObject|contains: '\Microsoft\Windows NT\CurrentVersion\Accessibility\Configuration'
27 Details: '(Empty)'
28 filter_uninstallers:
29 Image|startswith: 'C:\Windows\Installer\MSI'
30 TargetObject|contains: 'Software\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs'
31 condition: selection and not 1 of filter_*
32falsepositives:
33 - Creation of non-default, legitimate at usage
34level: medium
References
Related rules
- Abuse of Service Permissions to Hide Services Via Set-Service
- Abuse of Service Permissions to Hide Services Via Set-Service - PS
- Abusing Print Executable
- Account Tampering - Suspicious Failed Logon Reasons
- Activity From Anonymous IP Address