logo

Detecting RegPwn by Behavior, Not Binary

ID: 8650cb31-6712-5fee-98e3-712c0a9bbeb8

STIX ID: report--8650cb31-6712-5fee-98e3-712c0a9bbeb8

Feed Name: Detect FYI

Threat Score
60/100

Date Published: 2026-03-23

Date Updated: 2026-04-19

Author: Omar Tarek Zayed

...
...

This hunt report presents a Kusto detection that reconstructs a multi-stage exploit narrative abusing osk.exe and Windows accessibility broker behavior: it correlates non-standard osk.exe launches, SYSTEM-brokered execution via atbroker/winlogon, symbolic link or session ATConfig registry activity, and writes to sensitive registry targets (service/run keys) to identify persistence or privilege escalation. The query groups events by DeviceId, SessionId and time buckets, extracts process and registry artifacts, and produces a staged view of observed activity to reduce fragile exact-match rules while preserving the attack story for effective hunting and alerting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.