09-12-2023 10:48 PM
For the last few hours we have been seeing an increasing number of 'Powershell command in registry data' findings.
They all look the same and report something similar:
File: | taskhostw.exe e6370920…58402728 |
Registry Key: | \USER\S-1-5-21-1514197063-1296195755-1265796959-7856\SOFTWARE\Microsoft\Windows\CurrentVersion\AppListBackup\ListOfTaskBackedUpTiles_2361862998 ListOfTaskBackedUpTiles_2360852998 |
Registry Set | \USER\S-1-5-21-1514197063-1296195755-1265796959-7856\SOFTWARE\Microsoft\Windows\CurrentVersion\AppListBackup\ListOfTaskBackedUpTiles_2361862998 |
09-14-2023 12:17 AM
No nothing to worry but it obviously looks like the behavioral monitoring mapped the way it was added to known tactics and techniques. Is there a new or updated group policy up and running that manipulates existing scheduled tasks? Not sure but I thought there's a way to mute alerts the get triggered.
09-15-2023 05:52 AM
We have opened a TAC on this. They are still investigating but it seems that more than one customer has been affected.
I am curious about the cause of this
09-15-2023 07:20 AM
By now it seems to get evolving with the last ms windows updates (patchday)...:-D
09-25-2023 06:32 AM
Did Cisco get back to you on this? I started seeing this in our environment this morning.
09-25-2023 06:49 AM
No, not yet. We opened a TAC almost two weeks ago, but got no response other than "we're investigating"... 🤷
09-27-2023 05:42 AM
Hi There,
Just wondering if you have heard anything yet? I have had a couple of alerts for the same issue.
Thanks.
09-28-2023 12:08 AM
> Sep 22: "Talos is currently working on improving the indicators of compromise. Unfortunately I do not have information about estimated time of putting this on production, but once I found out I will let you know immediately."
> Sep 27: "Engineering already improved the signatures so you should not see such False Positives anymore. Please confirm that everything is fine regarding this issue."
So supposedly it's fixed, but we're still getting alerts today...
09-28-2023 02:37 AM
Thanks for the info, fingers crossed it's fixed.
10-12-2023 07:54 AM
We still see those alerts. Does anyone have news?
10-12-2023 09:39 AM
We are still getting the alerts even though TAC has assured us several times that the problem is really fixed now...
10-26-2023 09:02 AM
This popped
11-06-2023 06:42 AM
I saw this on one of our hosts 10 times in the last month:
Registry Key: \USER\S-1-5-21-3581115410-45963113-3647916999-49065\SOFTWARE\Microsoft\Windows\CurrentVersion\AppListBackup\TotalListOfLastBackedUpTiles_2343873105
Let's hope this really is fixed.
11-21-2023 06:19 AM
Still continuing to pop up for us, only a couple workstations though. Last one was on November 18th on version 8.1.3.
11-23-2023 06:44 AM
We have multiple customers and this only pops up for users of a specific customer (specific org). TAC says it's fixed with the latest definition updates but it's not. I have sent them some data and they are investigating.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide