T1012 Query Registry — ATT&CK Technique
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software. The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from Query Registry during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Detection coverage (28)
- Potential Baby Shark Malware Activity high
- Operation Wocao Activity high
- Operation Wocao Activity - Security high
- Remote Registry Management Using Reg Utility medium
- Potential Registry Reconnaissance Via PowerShell Script medium
- Potential Configuration And Service Reconnaissance Via Reg.EXE medium
- Azure AD Health Monitoring Agent Registry Keys Access medium
- Azure AD Health Service Agents Registry Keys Access medium
- SAM Registry Hive Handle Request high
- SysKey Registry Keys Access high
- Exports Critical Registry Keys To a File high
- Exports Registry Key To a File low
- HackTool - PCHunter Execution high
- Registry Manipulation via WMI Stdregprov medium
- Registry Enumeration via WMI Stdregprov medium
- Windows Credential Access From Browser Password Store
- Windows Credentials from Password Stores Chrome Login Data Access
- Windows Credentials from Password Stores Chrome Extension Access
- Windows Credentials from Password Stores Chrome LocalState Access
- Windows Hosts File Access
- Windows Non Discord App Access Discord LevelDB
- Windows Post Exploitation Risk Behavior
- Windows Query Registry UnInstall Program List
- Windows Product Key Registry Query
- Windows Query Registry Browser List Application
- Windows Registry Entries Restored Via Reg
- Windows Registry Entries Exported Via Reg
- Windows Software Discovery Via PowerShell
Malware using this technique
- Epic
- DUSTTRAP
- Sibot
- FatDuke
- Hydraq
- SVCReady
- Mafalda
- TEARDROP
- HOPLIGHT
- Shark
- BlackByte Ransomware
- Azorult
- Clambling
- Volgmer
- njRAT
- ROKRAT
- Shamoon
- BabyShark
- Denis
- PowerSploit
- Pillowmint
- Carbon
- POWERSOURCE
- RedLine Stealer
- Carbanak
- REvil
- LitePower
- JPIN
- WINDSHIELD
- PlugX
- ZxxZ
- FELIXROOT
- DownPaper
- Reg
- BACKSPACE
- LiteDuke
- ZxShell
- TRANSLATEXT
- Taidoor
- Saint Bot
- OSInfo
- SynAck
- Uroburos
- Dtrack
- Milan
- Bazar
- SILENTTRINITY
- Bankshot
- DarkWatchman
- Qilin