{"id":"T1547.014","name":"Active Setup","url":"https://attack.mitre.org/techniques/T1547/014","tactics":["persistence","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0312","stix_id":"x-mitre-detection-strategy--ba8d3a5d-9ddc-4301-b021-84ca2c6854de","name":"Detect Active Setup Persistence via StubPath Execution","url":"https://attack.mitre.org/detectionstrategies/DET0312","analytics":[{"id":"AN0871","stix_id":"x-mitre-analytic--0be2ac94-5f56-4bdc-bf07-ec9ea08c8bb7","name":"Analytic 0871","description":"Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login.","url":"https://attack.mitre.org/detectionstrategies/DET0312#AN0871","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4672","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=12","data_component":"DC0056","data_component_name":"Windows Registry Key Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlate registry change and process execution within a specific user logon session (e.g., 5–10 minutes)"},{"field":"ParentProcessName","description":"Expected parent processes for Active Setup launched binaries (e.g., explorer.exe). Deviations may indicate abuse."},{"field":"StubPathValueEntropy","description":"Degree of randomness/uncommonness in StubPath values. High entropy may indicate obfuscation."},{"field":"SignedBinaryStatus","description":"Flag if launched binary in StubPath is unsigned or uncommon for baseline"},{"field":"RegistryKeyOwner","description":"Check which user/context added the Active Setup key to detect privilege abuse"}],"live":true,"detection_strategies":["DET0312"],"techniques":["T1547.014"]}],"live":true,"version":"1.0","techniques":["T1547.014"]}],"sigma_rules":[{"id":"c2c76b77-32be-4d1f-82c9-7e544bdfe0eb","title":"Potential Suspicious Activity Using SeCEdit","author":"Janantha Marasinghe","status":"test","level":"medium","date":"2022-11-18","modified":"2022-12-30","description":"Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy","references":["https://blueteamops.medium.com/secedit-and-i-know-it-595056dee53d","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/secedit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.discovery","attack.persistence","attack.credential-access","attack.privilege-escalation","attack.execution","attack.stealth","attack.defense-impairment","attack.t1685.001","attack.t1547.001","attack.t1505.005","attack.t1556.002","attack.t1685","attack.t1574.007","attack.t1564.002","attack.t1546.008","attack.t1546.007","attack.t1547.014","attack.t1547.010","attack.t1547.002","attack.t1557","attack.t1082"],"path":"rules/windows/process_creation/proc_creation_win_secedit_execution.yml","techniques":["T1685.001","T1547.001","T1505.005","T1556.002","T1685","T1574.007","T1564.002","T1546.008","T1546.007","T1547.014","T1547.010","T1547.002","T1557","T1082"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}