Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1112 Modify Registry |
MalwareBADCALL | BADCALL modifies the firewall Registry key |
| T1112 Modify Registry |
MalwareHiddenFace | HiddenFace can store its configuration file in the Registry. |
| T1112 Modify Registry |
MalwareHermeticWiper | HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items. |
| T1112 Modify Registry |
MalwarePysa | Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note. |
| T1112 Modify Registry |
MalwareKapeka | Kapeka writes persistent configuration information to the victim host registry. |
| T1112 Modify Registry |
MalwareLockBit 2.0 | LockBit 2.0 can create Registry keys to bypass UAC and for persistence. |
| T1112 Modify Registry |
MalwarePandora | Pandora can write an encrypted token to the Registry to enable processing of remote commands. |
| T1112 Modify Registry |
MalwareCobalt Strike | Cobalt Strike can modify Registry values within |
| T1112 Modify Registry |
MalwareSUNBURST | SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their |
| T1112 Modify Registry |
MalwareREvil | REvil can modify the Registry to save encryption parameters and system information. |
| T1112 Modify Registry |
MalwareValak | Valak has the ability to modify the Registry key |
| T1112 Modify Registry |
MalwareSamurai | The Samurai loader component can create multiple Registry keys to force the svchost.exe process to load the final backdoor. |
| T1112 Modify Registry |
MalwareTaidoor | Taidoor has the ability to modify the Registry on compromised hosts using |
| T1112 Modify Registry |
MalwarePoisonIvy | PoisonIvy creates a Registry subkey that registers a new system device. |
| T1112 Modify Registry |
MalwareNanoCore | NanoCore has the capability to edit the Registry. |
| T1112 Modify Registry |
MalwareTajMahal | TajMahal can set the |
| T1112 Modify Registry |
MalwareIPsec Helper | IPsec Helper can make arbitrary changes to registry keys based on provided input. |
| T1112 Modify Registry |
MalwareLoJax | LoJax has modified the Registry key |
| T1112 Modify Registry |
MalwareCardinal RAT | Cardinal RAT sets |
| T1112 Modify Registry |
MalwarePillowmint | Pillowmint has modified the Registry key |
| T1112 Modify Registry |
MalwareSysUpdate | SysUpdate can write its configuration file to |
| T1112 Modify Registry |
MalwareNerex | Nerex creates a Registry subkey that registers a new service. |
| T1112 Modify Registry |
MalwareClop | Clop can make modifications to Registry keys. |
| T1112 Modify Registry |
MalwareLokibot | Lokibot has modified the Registry as part of its UAC bypass process. |
| T1112 Modify Registry |
MalwarePoetRAT | PoetRAT has made registry modifications to alter its behavior upon execution. |
| T1112 Modify Registry |
MalwareCHOPSTICK | CHOPSTICK may modify Registry keys to store RC4 encrypted configuration information. |
| T1112 Modify Registry |
MalwareFELIXROOT | FELIXROOT deletes the Registry key |
| T1112 Modify Registry |
MalwareZxShell | ZxShell can create Registry entries to enable services to run. |
| T1112 Modify Registry |
MalwarenjRAT | njRAT can create, delete, or modify a specified Registry key or value. |
| T1112 Modify Registry |
MalwareHIUPAN | HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`. |
| T1112 Modify Registry |
MalwareComRAT | ComRAT has modified Registry values to store encrypted orchestrator code and payloads. |
| T1112 Modify Registry |
MalwaremetaMain | metaMain can write the process ID of a target process into the `HKEY_LOCAL_MACHINE\SOFTWARE\DDE\tpid` Registry value as part of its reflective loading activity. |
| T1112 Modify Registry |
MalwareKOCTOPUS | KOCTOPUS has added and deleted keys from the Registry. |
| T1112 Modify Registry |
MalwareQilin | Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages. |
| T1112 Modify Registry |
MalwareAgent Tesla | Agent Tesla can achieve persistence by modifying Registry key entries. |
| T1112 Modify Registry |
MalwareShadowPad | ShadowPad can modify the Registry to store and maintain a configuration block and virtual file system. |
| T1112 Modify Registry |
MalwareQakBot | QakBot can modify the Registry to store its configuration information in a randomly named subkey under |
| T1112 Modify Registry |
MalwareGelsemium | Gelsemium can modify the Registry to store its components. |
| T1112 Modify Registry |
MalwareWaterbear | Waterbear has deleted certain values from the Registry to load a malicious DLL. |
| T1112 Modify Registry |
MalwarePHOREAL | PHOREAL is capable of manipulating the Registry. |
| T1112 Modify Registry |
MalwareBitPaymer | BitPaymer can set values in the Registry to help in execution. |
| T1112 Modify Registry |
MalwareBACKSPACE | BACKSPACE is capable of deleting Registry keys, sub-keys, and values on a victim system. |
| T1112 Modify Registry |
MalwareADVSTORESHELL | ADVSTORESHELL is capable of setting and deleting Registry values. |
| T1112 Modify Registry |
MalwareWarzoneRAT | WarzoneRAT can create `HKCU\Software\Classes\Folder\shell\open\command` as a new registry key during privilege escalation. |
| T1112 Modify Registry |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can add, modify, and/or delete registry keys. It has changed the proxy configuration of a victim system by modifying the |
| T1112 Modify Registry |
ToolNPPSPY | NPPSPY modifies the Registry to record the malicious listener for output from the Winlogon process. |
| T1112 Modify Registry |
ToolSILENTTRINITY | SILENTTRINITY can modify registry keys, including to enable or disable Remote Desktop Protocol (RDP). |
| T1112 Modify Registry |
ToolAADInternals | AADInternals can modify registry keys as part of setting a new pass-through authentication agent. |
| T1112 Modify Registry |
ToolPcShare | PcShare can delete its persistence mechanisms from the registry. |
| T1112 Modify Registry |
ToolCSPY Downloader | CSPY Downloader can write to the Registry under the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.