LoFP LoFP / legitimate modification of screensaver

Techniques

Sample rules

Path To Screensaver Binary Modified

Description

Detects value modification of registry key containing path to binary used as screensaver.

Detection logic

condition: selection and not filter
filter:
  Image|endswith:
  - \rundll32.exe
  - \explorer.exe
selection:
  TargetObject|endswith: \Control Panel\Desktop\SCRNSAVE.EXE