Potential Configuration And Service Reconnaissance Via Reg.EXE

 Original Source: [Sigma source]
Title: Potential Configuration And Service Reconnaissance Via Reg.EXE
Status: test
Description:Detects the usage of "reg.exe" in order to query reconnaissance information from the registry. Adversaries may interact with the Windows registry to gather information about credentials, the system, configuration, and installed software.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1012/T1012.md
Author: Timur Zinniatullin, oscd.community
Date: 2019-10-21
modified:2023-02-05
Tags:
  • -'attack.discovery'
  • -'attack.t1012'
  • -'attack.t1007'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\reg.exe' OriginalFileName:'reg.exe'   selection_flag:
    CommandLine|contains: 'query'
  selection_key:
    CommandLine|contains:
      -'currentVersion\windows'
      -'winlogon\'
      -'currentVersion\shellServiceObjectDelayLoad'
      -'currentVersion\run'
      -'currentVersion\policies\explorer\run'
      -'currentcontrolset\services'

  condition:all of selection_*
Falsepositives:
  -Discord
Level: medium