T1112 Modify Registry — ATT&CK Technique
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API. The Registry may be modified in order to hide configuration information or malicious payloads via Obfuscated Files or Information. The Registry may also be modified to impair defenses, such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory. The Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system. Often Valid Accounts are required, along with access to the remote system's SMB/Windows Admin Shares for RPC communication. Finally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via Reg or other utilities using the Win32 API. Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.
Detection coverage (50)
- OceanLotus Registry Activity critical
- OilRig APT Schedule Task Persistence - Security critical
- OilRig APT Registry Persistence critical
- OilRig APT Activity critical
- OilRig APT Schedule Task Persistence - System critical
- Potential Ursnif Malware Activity - Registry high
- CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry high
- Blue Mockingbird high
- Blue Mockingbird - Registry high
- FlowCloud Registry Markers critical
- Blackbyte Ransomware Registry high
- Potential NetWire RAT Activity - Registry high
- Potential Raspberry Robin Registry Set Internet Settings ZoneMap low
- Remote Registry Management Using Reg Utility medium
- Access To .Reg/.Hive Files By Uncommon Applications low
- Microsoft Office Trusted Location Updated medium
- Service Binary in User Controlled Folder medium
- Remote Registry Lateral Movement high
- Potential Suspicious Registry File Imported Via Reg.EXE medium
- Reg Add Suspicious Paths high
- Potentially Suspicious Desktop Background Change Using Reg.EXE medium
- Enable LM Hash Storage - ProcCreation high
- RestrictedAdminMode Registry Value Tampering - ProcCreation high
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE high
- ETW Logging Disabled In .NET Processes - Registry high
- NetNTLM Downgrade Attack high
- Sysmon Channel Reference Deletion high
- Imports Registry Key From an ADS high
- Suspicious Registry Modification From ADS Via Regini.EXE high
- Registry Modification Via Regini.EXE low
- Imports Registry Key From a File medium
- Registry Modification Attempt Via VBScript - PowerShell medium
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE high
- Security Event Logging Disabled via MiniNt Registry Key - Process high
- ShimCache Flush high
- Run Once Task Execution as Configured in Registry low
- Non-privileged Usage of Reg or Powershell high
- Registry Modification of MS-settings Protocol Handler medium
- User Shell Folders Registry Modification via CommandLine high
- Suspicious VBoxDrvInst.exe Parameters medium
- Registry Modification Attempt Via VBScript medium
- Registry Manipulation via WMI Stdregprov medium
- Terminal Server Client Connection History Cleared - Registry high
- Potential Qakbot Registry Activity high
- Removal of Potential COM Hijacking Registry Keys medium
- Registry Entries For Azorult Malware critical
- Wdigest CredGuard Registry Modification high
- Run Once Task Configuration in Registry medium
- Disable Security Events Logging Adding Reg Key MiniNt high
- NetNTLM Downgrade Attack - Registry high
Malware using this technique
- CharmPower
- PlugX
- ShadowPad
- Netwalker
- Valak
- ROKRAT
- HOPLIGHT
- Catchamas
- gh0st RAT
- SynAck
- SLOTHFULMEDIA
- Conficker
- DCSrv
- SUNBURST
- Explosive
- PolyglotDuke
- PoisonIvy
- KOCTOPUS
- LockBit 3.0
- LoJax
- HIUPAN
- PHOREAL
- PoetRAT
- REvil
- BACKSPACE
- DarkWatchman
- Grandoreiro
- Taidoor
- Stuxnet
- TinyTurla
- FELIXROOT
- SMOKEDHAM
- Pillowmint
- PipeMon
- Mafalda
- CHOPSTICK
- BlackByte 2.0 Ransomware
- HermeticWiper
- WarzoneRAT
- Cobalt Strike
- TRANSLATEXT
- CSPY Downloader
- IPsec Helper
- Lokibot
- ZxShell
- Gelsemium
- WastedLocker
- metaMain
- ShrinkLocker
- BOOKWORM