splApache-2.0from splunk/security_content
Disabling Task Manager
The following analytic identifies modifications to the Windows registry that disable Task Manager. It leverages data from the Endpoint.Registry data model, specifically looking for changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableTaskMgr" with a value of "0x00000001". This activity is significant as it is commonly associated with malware such as RATs, Trojans, and worms, which disable Task Manager to prevent users from terminating malicious processes. If confirmed malicious, this could allow attackers to maintain persistence and control over the infected system.
Quality
67
FP risk
โ
Forks
0
Views
1
Rule source๐ locked
๐
Sign in to view the rule source
Free accounts can view the source for the top-ranked rules. Create one in seconds โ no credit card required.
Sign in โ