Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareCrimson | Crimson can check the Registry for the presence of |
| T1012 Query Registry |
MalwareTEARDROP | TEARDROP checked that |
| T1012 Query Registry |
MalwareDUSTTRAP | DUSTTRAP can enumerate Registry items. |
| T1012 Query Registry |
MalwarePUBLOAD | PUBLOAD has queried Registry values to identify software using `reg query`. |
| T1012 Query Registry |
MalwareWoody RAT | Woody RAT can search registry keys to identify antivirus programs on an compromised host. |
| T1012 Query Registry |
MalwareMafalda | Mafalda can enumerate Registry keys with all subkeys and values. |
| T1012 Query Registry |
MalwareHOPLIGHT | A variant of HOPLIGHT hooks lsass.exe, and lsass.exe then checks the Registry for the data value 'rdpproto' under the key |
| T1012 Query Registry |
MalwareWastedLocker | WastedLocker checks for specific registry keys related to the |
| T1012 Query Registry |
MalwareInvisiMole | InvisiMole can enumerate Registry values, keys, and data. |
| T1012 Query Registry |
MalwareVolgmer | Volgmer checks the system for certain Registry keys. |
| T1012 Query Registry |
MalwareTRANSLATEXT | TRANSLATEXT has queried the following registry key to check for installed Chrome extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist `. |
| T1012 Query Registry |
MalwareFatDuke | FatDuke can get user agent strings for the default browser from |
| T1012 Query Registry |
MalwareLucifer | Lucifer can check for existing stratum cryptomining information in |
| T1012 Query Registry |
MalwareRising Sun | Rising Sun has identified the OS product name from a compromised host by searching the registry for `SOFTWARE\MICROSOFT\Windows NT\ CurrentVersion | ProductName`. |
| T1012 Query Registry |
MalwareROKRAT | ROKRAT can access the |
| T1012 Query Registry |
MalwareDarkWatchman | DarkWatchman can query the Registry to determine if it has already been installed on the system. |
| T1012 Query Registry |
MalwarePlugX | PlugX can enumerate and query for information contained within the Windows Registry. |
| T1012 Query Registry |
MalwareReaver | Reaver queries the Registry to determine the correct Startup path to use for persistence. |
| T1012 Query Registry |
MalwareBisonal | Bisonal has used the RegQueryValueExA function to retrieve proxy information in the Registry. |
| T1012 Query Registry |
MalwareEpic | Epic uses the |
| T1012 Query Registry |
MalwareClambling | Clambling has the ability to enumerate Registry keys, including |
| T1012 Query Registry |
MalwareSVCReady | SVCReady can search for the `HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System` Registry key to gather system information. |
| T1012 Query Registry |
MalwareCarbanak | Carbanak checks the Registry key |
| T1012 Query Registry |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can retrieve system information, such as CPU speed, from Registry keys. |
| T1012 Query Registry |
MalwareSaint Bot | Saint Bot has used `check_registry_keys` as part of its environmental checks. |
| T1012 Query Registry |
MalwareCharmPower | CharmPower has the ability to enumerate `Uninstall` registry values. |
| T1012 Query Registry |
MalwareMori | Mori can read data from the Registry including from `HKLM\Software\NFC\IPA` and |
| T1012 Query Registry |
MalwareQUADAGENT | QUADAGENT checks if a value exists within a Registry key in the HKCU hive whose name is the same as the scheduled task it has created. |
| T1012 Query Registry |
MalwareBendyBear | BendyBear can query the host's Registry key at |
| T1012 Query Registry |
MalwareUroburos | Uroburos can query the Registry, typically `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds`, to find the key and path to decrypt and load its kernel driver and kernel driver loader. |
| T1012 Query Registry |
Malwaregh0st RAT | gh0st RAT has checked for the existence of a Service key to determine if it has already been installed on the system. |
| T1012 Query Registry |
MalwareShamoon | Shamoon queries several Registry keys to identify hard disk partitions to overwrite. |
| T1012 Query Registry |
MalwareRedLine Stealer | RedLine Stealer can query the Windows Registry. |
| T1012 Query Registry |
MalwareStoneDrill | StoneDrill has looked in the registry to find the default browser path. |
| T1012 Query Registry |
MalwareAttor | Attor has opened the registry and performed query searches. |
| T1012 Query Registry |
MalwareLitePower | LitePower can query the Registry for keys added to execute COM hijacking. |
| T1012 Query Registry |
MalwareQUIETCANARY | QUIETCANARY has the ability to retrieve information from the Registry. |
| T1012 Query Registry |
MalwareDerusbi | Derusbi is capable of enumerating Registry keys and values. |
| T1012 Query Registry |
MalwareBlackByte Ransomware | BlackByte Ransomware enumerates the Registry, specifically the `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options` key. |
| T1012 Query Registry |
MalwareSodaMaster | SodaMaster has the ability to query the Registry to detect a key specific to VMware. |
| T1012 Query Registry |
MalwareLiteDuke | LiteDuke can query the Registry to check for the presence of |
| T1012 Query Registry |
MalwareSibot | Sibot has queried the registry for proxy server information. |
| T1012 Query Registry |
MalwareZxxZ | ZxxZ can search the registry of a compromised host. |
| T1012 Query Registry |
MalwareWINDSHIELD | WINDSHIELD can gather Registry values. |
| T1012 Query Registry |
MalwareShark | Shark can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID. |
| T1012 Query Registry |
MalwareBazar | Bazar can query |
| T1012 Query Registry |
MalwareRATANKBA | RATANKBA uses the command |
| T1012 Query Registry |
MalwareKapeka | Kapeka queries registry values for stored configuration information. |
| T1012 Query Registry |
MalwareZebrocy | Zebrocy executes the |
| T1012 Query Registry |
MalwareFinFisher | FinFisher queries Registry values as part of its anti-sandbox checks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.