Detects the per-user Control Panel Desktop SCRNSAVE.EXE value being pointed at an executable in a user-writable location or a script host. Windows launches the configured screensaver under the logged-on user after the idle timeout, giving low-noise persistence; legitimate screensavers are signed .scr binaries in System32. The rule matched on logsource `registry_set`. Verify the event genuinely matches the described behavior, and not a known legitimate case. The rule matches on these fields — examine the exact value in the event:
Investigation queries (read-only):
Relevant defensive analysis techniques (MITRE D3FEND), to apply where the telemetry is available:
Known benign causes for this rule:
The rule's references — CTI context to qualify the incident: