
Summary
This detection rule identifies modifications made to the Windows registry that disable toast notifications. Specifically, it tracks changes to the registry path `SOFTWARE\Microsoft\Windows\CurrentVersion\PushNotifications\ToastEnabled`, where the value is set to `0x00000000`. Disabling toast notifications can obstruct users from receiving critical updates and notifications, which attackers, such as those using the Azorult malware, might exploit to evade defense mechanisms and maintain prolonged access to the affected system. If such changes are confirmed as malicious, it could result in undetected operations and further system compromise.
Categories
- Endpoint
- Windows
Data Sources
- Pod
- Windows Registry
ATT&CK Techniques
- T1112
Created: 2024-11-13