Sub-technique of T1552 Unsecured Credentials.View on attack.mitre.org
Adversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information that can be used by the system or other programs. Adversaries may query the Registry looking for credentials and passwords that have been stored for use by other programs or services. Sometimes these credentials are used for automatic logons.
Example commands to find Registry keys related to password information:
* Local Machine Hive: reg query HKLM /f password /t REG_SZ /s
* Current User Hive: reg query HKCU /f password /t REG_SZ /s
Rules on DetectionCode tagged with T1552.002.
| Rule | Level | Log source |
|---|---|---|
| Registry Export of Third-Party Credentials | high | windows / process_creation |
| SAM Registry Hive Handle Request | high | windows / NULL |
| Enumeration for 3rd Party Creds From CLI | medium | windows / process_creation |
| Enumeration for Credentials in Registry | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Add DefaultUser And Password In Registry | Anomaly | NULL | Sysmon EventID 12, Sysmon EventID 13 |
| Auto Admin Logon Registry Entry | TTP | NULL | Sysmon EventID 13 |
| Windows Credentials in Registry Reg Query | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT32 | APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry. |
| GroupRedCurl | |
| GroupVOID MANTICORE | VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from the Registry. |
| MalwareIceApple | IceApple can harvest credentials from local and remote host registries. |
| ToolPowerSploit | PowerSploit has several modules that search the Windows Registry for stored credentials: |
| ToolReg | Reg may be used to find credentials in the Windows Registry. |
| MalwareStrelaStealer | StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application. |
| MalwareTrickBot | TrickBot has retrieved PuTTY credentials by querying the |
| MalwareValak | Valak can use the clientgrabber module to steal e-mail credentials from the Registry. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.