ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1012×

99 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareSodaMaster

SodaMaster has the ability to query the Registry to detect a key specific to VMware.

T1012
Query Registry
MalwareLiteDuke

LiteDuke can query the Registry to check for the presence of HKCU\Software\KasperskyLab.

T1012
Query Registry
MalwareSibot

Sibot has queried the registry for proxy server information.

T1012
Query Registry
MalwareZxxZ

ZxxZ can search the registry of a compromised host.

T1012
Query Registry
MalwareWINDSHIELD

WINDSHIELD can gather Registry values.

T1012
Query Registry
MalwareShark

Shark can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID.

T1012
Query Registry
MalwareBazar

Bazar can query Windows\CurrentVersion\Uninstall for installed applications.

T1012
Query Registry
MalwareRATANKBA

RATANKBA uses the command reg query “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings”.

T1012
Query Registry
MalwareKapeka

Kapeka queries registry values for stored configuration information.

T1012
Query Registry
MalwareZebrocy

Zebrocy executes the reg query command to obtain information in the Registry.

T1012
Query Registry
MalwareFinFisher

FinFisher queries Registry values as part of its anti-sandbox checks.

T1012
Query Registry
MalwareCobalt Strike

Cobalt Strike can query HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to determine if the security setting for restricting default programmatic access is enabled.

T1012
Query Registry
MalwareSUNBURST

SUNBURST collected the registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid from compromised hosts.

T1012
Query Registry
MalwareREvil

REvil can query the Registry to get random file extensions to append to encrypted files.

T1012
Query Registry
MalwareValak

Valak can use the Registry for code updates and to collect credentials.

T1012
Query Registry
MalwareSamurai

Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery.

T1012
Query Registry
MalwareMilan

Milan can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID.

T1012
Query Registry
MalwareTaidoor

Taidoor can query the Registry on compromised hosts using RegQueryValueExA.

T1012
Query Registry
MalwareRaccoon Stealer

Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key.

T1012
Query Registry
MalwareCarbon

Carbon enumerates values in the Registry.

T1012
Query Registry
MalwareCardinal RAT

Cardinal RAT contains watchdog functionality that periodically ensures HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load is set to point to its executable.

T1012
Query Registry
MalwareGold Dragon

Gold Dragon enumerates registry keys with the command regkeyenum and obtains information for the Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1012
Query Registry
MalwareCarberp

Carberp has searched the Image File Execution Options registry key for "Debugger" within every subkey.

T1012
Query Registry
MalwarePillowmint

Pillowmint has used shellcode which reads code stored in the registry keys \REGISTRY\SOFTWARE\Microsoft\DRM using the native Windows API as well as read HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces as part of its C2.

T1012
Query Registry
MalwareFunnyDream

FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string.

T1012
Query Registry
MalwareCHOPSTICK

CHOPSTICK provides access to the Windows Registry, which can be used to gather information.

T1012
Query Registry
MalwareFELIXROOT

FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry.

T1012
Query Registry
MalwareZxShell

ZxShell can query the netsvc group value data located in the svchost group Registry key.

T1012
Query Registry
MalwareBabyShark

BabyShark has executed the reg query command for HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default.

T1012
Query Registry
MalwarenjRAT

njRAT can read specific registry values.

T1012
Query Registry
MalwareComRAT

ComRAT can check the default browser by querying HKCR\http\shell\open\command.

T1012
Query Registry
MalwareJPIN

JPIN can enumerate Registry keys.

T1012
Query Registry
MalwareQilin

Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.

T1012
Query Registry
MalwareIndustroyer

Industroyer has a data wiper component that enumerates keys in the Registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services.

T1012
Query Registry
MalwareDownPaper

DownPaper searches and reads the value of the Windows Update Registry Run key.

T1012
Query Registry
MalwareGelsemium

Gelsemium can open random files and Registry keys to obscure malware behavior from sandbox analysis.

T1012
Query Registry
MalwareDenis

Denis queries the Registry for keys and values.

T1012
Query Registry
MalwareWaterbear

Waterbear can query the Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\MTxOCI" to see if the value `OracleOcilib` exists.

T1012
Query Registry
MalwareOSInfo

OSInfo queries the registry to look for information about Terminal Services.

T1012
Query Registry
MalwareDtrack

Dtrack can collect the RegisteredOwner, RegisteredOrganization, and InstallDate registry values.

T1012
Query Registry
MalwareAzorult

Azorult can check for installed software on the system under the Registry key Software\Microsoft\Windows\CurrentVersion\Uninstall.

T1012
Query Registry
MalwareBitPaymer

BitPaymer can use the RegEnumKeyW to iterate through Registry keys.

T1012
Query Registry
MalwareBACKSPACE

BACKSPACE is capable of enumerating and making modifications to an infected system's Registry.

T1012
Query Registry
MalwareADVSTORESHELL

ADVSTORESHELL can enumerate registry keys.

T1012
Query Registry
ToolSILENTTRINITY

SILENTTRINITY can use the `GetRegValue` function to check Registry keys within `HKCU\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated`. It also contains additional modules that can check software AutoRun values and use the Win32 namespace to get values from HKCU, HKLM, HKCR, and HKCC hives.

T1012
Query Registry
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can query Registry keys for potential opportunities.

T1012
Query Registry
ToolPcShare

PcShare can search the registry files of a compromised host.

T1012
Query Registry
ToolRemcos

Remcos can obtain Registry data from targeted systems.

T1012
Query Registry
ToolReg

Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.