name: Windows Disable Notification Center id: 1cd983c8-8fd6-11ec-a09d-acde48001122 version: 1 date: '2022-02-17' author: Teoderick Contreras, Splunk status: production type: Anomaly description: The following search identifies a modification of registry to disable the windows notification center feature in a windows host machine. This registry modification removes notification and action center from the notification area on the task bar. This modification are seen in RAT malware to cover their tracks upon downloading other of its component or other payload. data_source: - Sysmon Event ID 13 search: selection1: Details: '0x00000001' Registry.registry_value_name: DisableNotificationCenter condition: selection1 how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config files ex. sysmon config to be monitored. known_false_positives: admin or user may choose to disable this windows features. references: - https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html tags: analytic_story: - Windows Defense Evasion Tactics - Windows Registry Abuse asset_type: Endpoint confidence: 80 impact: 60 message: The Windows notification center was disabled on $dest$ by $user$. mitre_attack_id: - T1112 observable: - name: user type: User role: - Victim - name: dest type: Hostname role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud risk_score: 48 security_domain: endpoint tests: - name: True Positive Test attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/disable_notif_center/sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog