Hunting Fileless Malware in the Windows Registry
ID: 01c2e170-a217-5177-9f29-0d2d5c9967d1
STIX ID: report--01c2e170-a217-5177-9f29-0d2d5c9967d1
Feed Name: Detect FYI
This report documents fileless malware techniques that leverage the Windows Registry for payload staging and persistence and provides practical Microsoft Defender for Endpoint hunting analytics. It explains how common LOLBins (e.g., powershell.exe, reg.exe, wscript.exe, mshta.exe, rundll32.exe) can write encoded payloads into HKCU, illustrates attack scenarios and artifacts, and presents a set of KQL queries to detect suspicious registry activity including length-based outliers, hex/blob pattern detection, registry write bursts, indirect execution chains, and writes to uncommon HKCU keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
