LoFP LoFP / t1112

t1112

TitleTags
administrative activity, still unlikely
administrative scripts that change the desktop background to a company logo or other image.
evernote
highly unlikely
legitimate admin script
legitimate disabling of crashdumps
legitimate import of keys
legitimate internal requirements.
legitimate modification of keys
legitimate modification of the registry key by legitimate program
legitimate software (un)installations are known to cause false positives. please add them as a filter when encountered
legitimate use of external db to save the results
legitimate use of the feature (alerts should be investigated either way)
legitimate use of the multi session functionality
legitimate use of vboxdrvinst.exe utility by virtualbox guest additions installation process
legitimate vbscript
legitimate windows defender configuration changes
legitimate wmi query
many legitimate applications can register a new custom protocol handler. additional filters needs to applied according to your environment.
other unknown legitimate or custom paths need to be filtered to avoid false positives
rare legitimate add to registry via cli (to these locations)
remote administration of registry values
services or tools that set the values to more restrictive values
some legitimate admin or install scripts may use these processes for registry modifications.
some of the keys mentioned here could be modified by an administrator while setting group policy (it should be investigated either way)
unknown
unlikely
usage of reg.exe or powershell to modify user shell folders for legitimate purposes; but rare.