Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
GroupIndrik Spider | Indrik Spider has used a service account to extract copies of the `Security` Registry hive. |
| T1012 Query Registry |
GroupBlackByte | BlackByte queried registry values to determine system language settings. |
| T1012 Query Registry |
GroupKimsuky | Kimsuky has obtained specific Registry keys and values on a compromised host. |
| T1012 Query Registry |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY. |
| T1012 Query Registry |
GroupAPT41 | APT41 queried registry values to determine items such as configured RDP ports and network configurations. |
| T1012 Query Registry |
GroupDragonfly | Dragonfly has queried the Registry to identify victim information. |
| T1012 Query Registry |
GroupAPT32 | APT32's backdoor can query the Windows Registry to gather system information. |
| T1012 Query Registry |
GroupGamaredon Group | Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. |
| T1012 Query Registry |
GroupZIRCONIUM | ZIRCONIUM has used a tool to query the Registry for proxy settings. |
| T1012 Query Registry |
GroupAPT39 | APT39 has used various strains of malware to query the Registry. |
| T1012 Query Registry |
GroupOilRig | OilRig has used |
| T1012 Query Registry |
GroupTurla | Turla surveys a system upon check-in to discover information in the Windows Registry with the |
| T1012 Query Registry |
GroupLotus Blossom | Lotus Blossom has run commands such as `reg query HKLM\SYSTEM\CurrentControlSet\Services\[service name]\Parameters` to verify if installed implants are running as a service. |
| T1012 Query Registry |
GroupStealth Falcon | Stealth Falcon malware attempts to determine the installed version of .NET by querying the Registry. |
| T1012 Query Registry |
GroupChimera | Chimera has queried Registry keys using |
| T1012 Query Registry |
GroupFox Kitten | Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat. |
| T1012 Query Registry |
GroupLazarus Group | Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key: |
| T1012 Query Registry |
GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines. |
| T1012 Query Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool can read and decrypt stored Registry values. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.