BIOC
Medium
✕
WerFault ReflectDebugger key set in Registry
The WerFault.exe signed Windows process may be tricked into running a malicious executable by setting the ReflectDebugger key in the Registry.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution (T1218)
Indicator:
Registry action type = create_registry_key , delete_registry_key , rename_registry_key , set_registry_value AND registry value name = *reflectdebugger* Host host os = windows
Preventable: yes