heroui logo

Disabled IE Security Features

Sigma Rules

View Source
Summary
This detection rule identifies potentially malicious activities related to the modification of Internet Explorer security settings through command line inputs. The rule specifically looks for registry modifications that disable critical security features in Internet Explorer. It focuses on three specific registry keys: `IEHarden`, `DEPOff`, and `DisableFirstRunCustomize`, detecting changes that suggest these features are being deactivated. The presence of command line arguments indicating these modifications can signal an attempt to compromise system security, making this an important rule for monitoring malicious behavior related to browser security features.
Categories
  • Endpoint
  • Windows
  • Application
Data Sources
  • Process
Created: 2020-06-19