Detection rules › Equivalence class

eq_0007 — 2 rules with the same canonical form

Vendors: sigma (2). Stage count: 4. Correlation shape: single_event.

Members

MITRE ATT&CK coverage

TacticTechniques
DiscoveryT1012 Query Registry

Stages and predicates (per member)

Each member's stage rendered in its own native syntax (verbatim source where the IR captures it; falls back to the synthesised native form for the few stage types whose source segments aren't recoverable).

Exports Critical Registry Keys To a File — stage 1 all of selection_img

or:
Image|endswith: '\regedit.exe'
OriginalFileName: REGEDIT.EXE

Exports Critical Registry Keys To a File — stage 2 all of selection_cli_1

CommandLine|contains: ' -E '

Exports Critical Registry Keys To a File — stage 3 all of selection_cli_2

or:
CommandLine|contains: hkey_local_machine
CommandLine|contains: hklm

Exports Critical Registry Keys To a File — stage 4 all of selection_cli_3

or:
CommandLine|endswith: '\sam'
CommandLine|endswith: '\security'
CommandLine|endswith: '\system'

Exports Registry Key To a File — stage 5 all of selection_img

or:
Image|endswith: '\regedit.exe'
OriginalFileName: REGEDIT.EXE

Exports Registry Key To a File — stage 6 all of selection_cli

CommandLine|contains: ' -E '

Exports Registry Key To a File — stage 7 not all of filter_1

or:
CommandLine|contains: hkey_local_machine
CommandLine|contains: hklm

Exports Registry Key To a File — stage 8 not all of filter_2

or:
CommandLine|endswith: '\sam'
CommandLine|endswith: '\security'
CommandLine|endswith: '\system'

Indicators (across all members)

FieldKindValueMembersCorpus
CommandLineends_with\sam22
CommandLineends_with\security22
CommandLineends_with\system22
CommandLinematch -E 22
CommandLinematchhkey_local_machine23
CommandLinematchhklm23
Imageends_with\regedit.exe28
OriginalFileNameeqREGEDIT.EXE24