Dumping of Sensitive Hives Via Reg.EXE

 Original Source: [Sigma source]
Title: Dumping of Sensitive Hives Via Reg.EXE
Status: test
Description:Detects the usage of "reg.exe" in order to dump sensitive registry hives. This includes SAM, SYSTEM and SECURITY hives.
References:
  -https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
  -https://eqllib.readthedocs.io/en/latest/analytics/aed95fc6-5e3f-49dc-8b35-06508613f979.html
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003/T1003.md
  -https://www.wietzebeukema.nl/blog/windows-command-line-obfuscation
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets
Author: Teymur Kheirkhabarov, Endgame, JHasenbusch, Daniil Yugoslavskiy, oscd.community, frack113
Date: 2019-10-22
modified:2023-12-13
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
  • -'attack.t1003.004'
  • -'attack.t1003.005'
  • -'car.2013-07-001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\reg.exe' OriginalFileName:'reg.exe'   selection_cli_flag:
    CommandLine|contains:
      -' save '
      -' export '
      -' ˢave '
      -' eˣport '

  selection_cli_hklm:
    CommandLine|contains:
      -'hklm'
      -'hk˪m'
      -'hkey_local_machine'
      -'hkey_˪ocal_machine'
      -'hkey_loca˪_machine'
      -'hkey_˪oca˪_machine'

  selection_cli_hive:
    CommandLine|contains:
      -'\system'
      -'\sam'
      -'\security'
      -'\ˢystem'
      -'\syˢtem'
      -'\ˢyˢtem'
      -'\ˢam'
      -'\ˢecurity'

  condition:all of selection_*
Falsepositives:
  -Dumping hives for legitimate purpouse i.e. backup or forensic investigation
Level: high