logo

Hunting Fileless Malware in the Windows Registry

ID: 01c2e170-a217-5177-9f29-0d2d5c9967d1

STIX ID: report--01c2e170-a217-5177-9f29-0d2d5c9967d1

Feed Name: Detect FYI

Threat Score
30/100

Date Published: 2025-06-24

Date Updated: 2026-04-19

Author: Manuel Arrieta

...
...

This report documents fileless malware techniques that leverage the Windows Registry for payload staging and persistence and provides practical Microsoft Defender for Endpoint hunting analytics. It explains how common LOLBins (e.g., powershell.exe, reg.exe, wscript.exe, mshta.exe, rundll32.exe) can write encoded payloads into HKCU, illustrates attack scenarios and artifacts, and presents a set of KQL queries to detect suspicious registry activity including length-based outliers, hex/blob pattern detection, registry write bursts, indirect execution chains, and writes to uncommon HKCU keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.