T1112 Modify Registry — ATT&CK Technique
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API. The Registry may be modified in order to hide configuration information or malicious payloads via Obfuscated Files or Information. The Registry may also be modified to impair defenses, such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory. The Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system. Often Valid Accounts are required, along with access to the remote system's SMB/Windows Admin Shares for RPC communication. Finally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via Reg or other utilities using the Win32 API. Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.
Detection coverage (50)
- Potential Raspberry Robin Registry Set Internet Settings ZoneMap low
- Remote Registry Management Using Reg Utility medium
- Access To .Reg/.Hive Files By Uncommon Applications low
- Microsoft Office Trusted Location Updated medium
- Service Binary in User Controlled Folder medium
- Remote Registry Lateral Movement high
- Potential Suspicious Registry File Imported Via Reg.EXE medium
- Reg Add Suspicious Paths high
- Potentially Suspicious Desktop Background Change Using Reg.EXE medium
- Enable LM Hash Storage - ProcCreation high
- RestrictedAdminMode Registry Value Tampering - ProcCreation high
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE high
- ETW Logging Disabled In .NET Processes - Registry high
- NetNTLM Downgrade Attack high
- Sysmon Channel Reference Deletion high
- Imports Registry Key From an ADS high
- Suspicious Registry Modification From ADS Via Regini.EXE high
- Registry Modification Via Regini.EXE low
- Imports Registry Key From a File medium
- Registry Modification Attempt Via VBScript - PowerShell medium
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE high
- Security Event Logging Disabled via MiniNt Registry Key - Process high
- ShimCache Flush high
- Run Once Task Execution as Configured in Registry low
- Non-privileged Usage of Reg or Powershell high
- Registry Modification of MS-settings Protocol Handler medium
- User Shell Folders Registry Modification via CommandLine high
- Suspicious VBoxDrvInst.exe Parameters medium
- Registry Modification Attempt Via VBScript medium
- Registry Manipulation via WMI Stdregprov medium
- Terminal Server Client Connection History Cleared - Registry high
- Potential Qakbot Registry Activity high
- Removal of Potential COM Hijacking Registry Keys medium
- Registry Entries For Azorult Malware critical
- Wdigest CredGuard Registry Modification high
- Run Once Task Configuration in Registry medium
- Disable Security Events Logging Adding Reg Key MiniNt high
- NetNTLM Downgrade Attack - Registry high
- RedMimicry Winnti Playbook Registry Manipulation high
- Registry Tampering by Potentially Suspicious Processes medium
- Allow RDP Remote Assistance Feature medium
- New BgInfo.EXE Custom DB Path Registry Configuration medium
- ClickOnce Trust Prompt Tampering medium
- Service Binary in Suspicious Folder high
- New BgInfo.EXE Custom WMI Query Registry Configuration medium
- CrashControl CrashDump Disabled medium
- New BgInfo.EXE Custom VBScript Registry Configuration medium
- Security Event Logging Disabled via MiniNt Registry Key - Registry Set high
- DHCP Callout DLL Installation high
- Disable Windows Security Center Notifications medium
Malware using this technique
- TrickBot
- RCSession
- SynAck
- Exaramel for Windows
- Amadey
- Orz
- Stuxnet
- PipeMon
- KEYMARBLE
- Ursnif
- ThreatNeedle
- Zeus Panda
- ShimRat
- Prestige
- Bankshot
- PLAINTEE
- TinyTurla
- MegaCortex
- StreamEx
- BOOKWORM
- HyperStack
- GreyEnergy
- Crimson
- TEARDROP
- Clambling
- Mafalda
- PolyglotDuke
- ShrinkLocker
- BlackByte 2.0 Ransomware
- HOPLIGHT
- DarkWatchman
- WastedLocker
- RegDuke
- InvisiMole
- Naid
- Volgmer
- TRANSLATEXT
- Regin
- Neoichor
- AADInternals
- BlackCat
- PowerShower
- DarkComet
- CHIMNEYSWEEP
- zwShell
- DCSrv
- IPsec Helper
- Avaddon
- Conficker
- DarkTortilla