Windows Downdate Registry Activity — Detection Rule

Detects the setting of a pending.xml file associated with the Windows Downdate attack which forces a Windows downgrade to enable exploitation. Looks for uses of a pending.xml outside of typical locations.

Read the full analysis on IntelFusions