
Summary
Detects attempts to conceal software from Programs and Features by either executing the Hide From Uninstall List (HideUL) utility or modifying registry values to mark an application as a SystemComponent. The rule correlates process events (HideUL.exe or HideUL_x64.exe) or process original file name with registry changes that set SystemComponent under uninstall subkeys in the Windows registry, excluding specific legitimate contexts (e.g., EdgeWebView SystemComponent) and a particular MSI-elevated scenario. This combination signals potential defense evasion through artifact hiding (T1564) and registry modification (T1112). Data sources include Sysmon process creation events and Windows Registry changes, integrated via Elastic Defend and Windows log streams. The rule is intended for Windows endpoints and supports investigator workflows to identify which app was concealed, how it was launched, and whether concealment occurred across multiple hosts, guiding containment, remediation, and evidence preservation.
Categories
- Endpoint
- Windows
Data Sources
- Process
- Windows Registry
ATT&CK Techniques
- T1564
- T1112
Created: 2026-09-17