heroui logo

IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols

Sigma Rules

View Source
Summary
This detection rule identifies changes to the Windows Internet Explorer ZoneMap settings that potentially compromise security. Specifically, it monitors modifications to the registry settings related to the HTTP and HTTPS protocols. If these settings are altered to assign the "My Computer" security zone, downloaded files from the Internet could be treated with the same trust level as local files, heightening the risk of malware execution and unauthorized access. The rule targets the registry path 'HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults' and checks for a DWORD value of 0x00000000, which indicates such a downgrade in trust. By flagging these changes, the rule provides an opportunity to mitigate risks associated with less restrictive security settings for Internet downloads, thereby enhancing overall system protection.
Categories
  • Windows
  • Endpoint
Data Sources
  • Windows Registry
Created: 2023-09-05