Skip to content

Hide Navigation Hide TOC

RunMRU Registry Key Deletion - Registry (3a9b8c1e-5b2e-4f7a-9d1c-2a7f3b6e1c55)

Detects attempts to delete the RunMRU registry key, which stores the history of commands executed via the run dialog. In the clickfix techniques, the phishing lures instruct users to open a run dialog through (Win + R) and execute malicious commands. Adversaries may delete this key to cover their tracks after executing commands.

Cluster A Galaxy A Cluster B Galaxy B Level
RunMRU Registry Key Deletion - Registry (3a9b8c1e-5b2e-4f7a-9d1c-2a7f3b6e1c55) Sigma-Rules Clear Command History - T1070.003 (3aef9463-9a7a-43ba-8957-a867e07c1e6a) Attack Pattern 1
Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern Clear Command History - T1070.003 (3aef9463-9a7a-43ba-8957-a867e07c1e6a) Attack Pattern 2