title: Potential KamiKakaBot Activity - Winlogon Shell Persistence id: c9b86500-1ec2-4de6-9120-d744c8fb5caf status: test description: | Detects changes to the "Winlogon" registry key where a process will set the value of the "Shell" to a value that was observed being used by KamiKakaBot samples in order to achieve persistence. references: - https://www.nextron-systems.com/2024/03/22/unveiling-kamikakabot-malware-analysis/ author: Nasreddine Bencherchali (Nextron Systems), X__Junior date: 2024-03-22 tags: - attack.privilege-escalation - attack.persistence - attack.t1547.001 - detection.emerging-threats logsource: category: registry_set product: windows detection: selection: TargetObject|endswith: '\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell' Details|contains|all: - '-nop -w h' - '$env' - 'explorer.exe' - 'Start-Process' condition: selection falsepositives: - Unlikely level: high