Registry Export of Third-Party Credentials — Detection Rule

Detects the use of reg.exe to export registry paths associated with third-party credentials. Credential stealers have been known to use this technique to extract sensitive information from the registry.

Read the full analysis on IntelFusions