Detection rules › Sigma

MaxMpxCt Registry Value Changed

Severity
low
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects changes to the "MaxMpxCt" registry value. MaxMpxCt specifies the maximum outstanding network requests for the server per client, which is used when negotiating a Server Message Block (SMB) connection with a client. Note if the value is set beyond 125 older Windows 9x clients will fail to negotiate. Ransomware threat actors and operators (specifically BlackCat) were seen increasing this value in order to handle a higher volume of traffic.

MITRE ATT&CK coverage

TacticTechniques
Defense EvasionT1070.005 Indicator Removal: Network Share Connection Removal

Event coverage

ProviderEvent IDTitle
Sysmon13RegistryEvent (Value Set)

Stages and Predicates

Stage 1: selection

TargetObject|endswith: '\Services\LanmanServer\Parameters\MaxMpxCt'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
TargetObjectends_with
  • \Services\LanmanServer\Parameters\MaxMpxCt