BIOC
Medium
✕
Process changes the Windows logon text
This registry key is used to display a legal notice when logging on to the computer. This is used by the DXXD ransomware to notify the user.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Tampering
- Status:
- Enabled
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Defacement (T1491)
Indicator:
Registry action type = create_registry_key , set_registry_value , rename_registry_key AND registry key name = *SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeCaption* Host host os = windows
Preventable: yes