LoFP LoFP / this value is not set by default but could be rarly used by administrators

Techniques

Sample rules

Add Debugger Entry To Hangs Key For Persistence

Description

Detects when an attacker adds a new “Debugger” value to the “Hangs” key in order to achieve persistence which will get invoked when an application crashes

Detection logic

condition: selection
selection:
  TargetObject|contains: \SOFTWARE\Microsoft\Windows\Windows Error Reporting\Hangs\Debugger