LoFP LoFP / legitimate use of external db to save the results

Techniques

Sample rules

New BgInfo.EXE Custom DB Path Registry Configuration

Description

Detects setting of a new registry database value related to BgInfo configuration. Attackers can for example set this value to save the results of the commands executed by BgInfo in order to exfiltrate information.

Detection logic

condition: selection
selection:
  EventType: SetValue
  TargetObject|endswith: \Software\Winternals\BGInfo\Database