Technique.View on attack.mitre.org
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from Query Registry during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Rules on DetectionCode tagged with T1012.
| Rule | Level | Log source |
|---|---|---|
| Exports Critical Registry Keys To a File | high | windows / process_creation |
| HackTool - PCHunter Execution | high | windows / process_creation |
| SAM Registry Hive Handle Request | high | windows / NULL |
| SysKey Registry Keys Access | high | windows / NULL |
| Azure AD Health Monitoring Agent Registry Keys Access | medium | windows / NULL |
| Azure AD Health Service Agents Registry Keys Access | medium | windows / NULL |
| Potential Configuration And Service Reconnaissance Via Reg.EXE | medium | windows / process_creation |
| Registry Enumeration via WMI Stdregprov | medium | windows / process_creation |
| Exports Registry Key To a File | low | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Credential Access From Browser Password Store | Anomaly | NULL | Windows Event Log Security 4663 |
| Windows Credentials from Password Stores Chrome Extension Access | Anomaly | NULL | Windows Event Log Security 4663 |
| Windows Credentials from Password Stores Chrome LocalState Access | Anomaly | NULL | Windows Event Log Security 4663 |
| Windows Credentials from Password Stores Chrome Login Data Access | Anomaly | NULL | Windows Event Log Security 4663 |
| Windows Hosts File Access | Anomaly | NULL | Windows Event Log Security 4663 |
| Windows Modify Registry Reg Restore | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Non Discord App Access Discord LevelDB | Anomaly | NULL | Windows Event Log Security 4663 |
| Windows Post Exploitation Risk Behavior | Correlation | NULL | |
| Windows Product Key Registry Query | Anomaly | NULL | Windows Event Log Security 4663 |
| Windows Query Registry Browser List Application | Anomaly | NULL | Windows Event Log Security 4663 |
| Windows Query Registry Reg Save | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Query Registry UnInstall Program List | Anomaly | NULL | Windows Event Log Security 4663 |
| Windows Registry Entries Exported Via Reg | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Registry Entries Restored Via Reg | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Software Discovery Via PowerShell | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Used by | Procedure example |
|---|---|
| GroupAPT32 | APT32's backdoor can query the Windows Registry to gather system information. |
| GroupAPT39 | APT39 has used various strains of malware to query the Registry. |
| GroupAPT41 | APT41 queried registry values to determine items such as configured RDP ports and network configurations. |
| GroupBlackByte | BlackByte queried registry values to determine system language settings. |
| GroupChimera | Chimera has queried Registry keys using |
| GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines. |
| GroupDragonfly | Dragonfly has queried the Registry to identify victim information. |
| GroupFox Kitten | Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat. |
| Used by | Procedure example |
|---|---|
| MalwareADVSTORESHELL | ADVSTORESHELL can enumerate registry keys. |
| MalwareAttor | Attor has opened the registry and performed query searches. |
| MalwareAzorult | Azorult can check for installed software on the system under the Registry key |
| MalwareBabyShark | BabyShark has executed the |
| MalwareBACKSPACE | BACKSPACE is capable of enumerating and making modifications to an infected system's Registry. |
| MalwareBankshot | Bankshot searches for certain Registry keys to be configured before executing the payload. |
| MalwareBazar | Bazar can query |
| MalwareBendyBear | BendyBear can query the host's Registry key at |
| Used by | Procedure example |
|---|---|
| CampaignOperation Wocao | During Operation Wocao, the threat actors executed `/c cd /d c:\windows\temp\ & reg query HKEY_CURRENT_USER\Software\<username>\PuTTY\Sessions\` to detect recent PuTTY sessions, likely to further lateral movement. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.