Skip to content

Potential Persistence via IFEO and SilentProcessExit Registry Keys

This detection identifies suspicious modifications to the Image File Execution Options (IFEO) and SilentProcessExit registry keys. Attackers commonly abuse these keys for persistence, evasion, or process injection by setting values such as Debugger, GlobalFlag, ReportingMode, and MonitorProcess. Monitoring these changes helps surface attempts at persistence or stealthy process monitoring.

Detection details

Tactic Technique Author Date
Persistence T1546.012, Event Triggered Execution: Image File Execution Options Injection Rory Wagner (Sleuthifer) 2025-08-29

References

Query

DeviceRegistryEvents
| where RegistryKey startswith @"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options"
    or RegistryKey startswith @"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit"
| where RegistryValueName in~ ("Debugger", "GlobalFlag", "ReportingMode", "MonitorProcess")

View source on GitHub