Real-world descriptions of how a group, tool or campaign used a technique.
139 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1112 Modify Registry |
MalwareTajMahal | TajMahal can set the |
| T1112 Modify Registry |
MalwareIPsec Helper | IPsec Helper can make arbitrary changes to registry keys based on provided input. |
| T1112 Modify Registry |
MalwareLoJax | LoJax has modified the Registry key |
| T1112 Modify Registry |
MalwareCardinal RAT | Cardinal RAT sets |
| T1112 Modify Registry |
MalwarePillowmint | Pillowmint has modified the Registry key |
| T1112 Modify Registry |
MalwareSysUpdate | SysUpdate can write its configuration file to |
| T1112 Modify Registry |
MalwareNerex | Nerex creates a Registry subkey that registers a new service. |
| T1112 Modify Registry |
MalwareClop | Clop can make modifications to Registry keys. |
| T1112 Modify Registry |
MalwareLokibot | Lokibot has modified the Registry as part of its UAC bypass process. |
| T1112 Modify Registry |
MalwarePoetRAT | PoetRAT has made registry modifications to alter its behavior upon execution. |
| T1112 Modify Registry |
MalwareCHOPSTICK | CHOPSTICK may modify Registry keys to store RC4 encrypted configuration information. |
| T1112 Modify Registry |
MalwareFELIXROOT | FELIXROOT deletes the Registry key |
| T1112 Modify Registry |
MalwareZxShell | ZxShell can create Registry entries to enable services to run. |
| T1112 Modify Registry |
MalwarenjRAT | njRAT can create, delete, or modify a specified Registry key or value. |
| T1112 Modify Registry |
MalwareHIUPAN | HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`. |
| T1112 Modify Registry |
MalwareComRAT | ComRAT has modified Registry values to store encrypted orchestrator code and payloads. |
| T1112 Modify Registry |
MalwaremetaMain | metaMain can write the process ID of a target process into the `HKEY_LOCAL_MACHINE\SOFTWARE\DDE\tpid` Registry value as part of its reflective loading activity. |
| T1112 Modify Registry |
MalwareKOCTOPUS | KOCTOPUS has added and deleted keys from the Registry. |
| T1112 Modify Registry |
MalwareQilin | Qilin can make Registry modifications to share networked drives between elevated and non-elevated processes and to increase the number of outstanding network requests per client. Qilin can also modify `HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper` to enable posting of ransom messages. |
| T1112 Modify Registry |
MalwareAgent Tesla | Agent Tesla can achieve persistence by modifying Registry key entries. |
| T1112 Modify Registry |
MalwareShadowPad | ShadowPad can modify the Registry to store and maintain a configuration block and virtual file system. |
| T1112 Modify Registry |
MalwareQakBot | QakBot can modify the Registry to store its configuration information in a randomly named subkey under |
| T1112 Modify Registry |
MalwareGelsemium | Gelsemium can modify the Registry to store its components. |
| T1112 Modify Registry |
MalwareWaterbear | Waterbear has deleted certain values from the Registry to load a malicious DLL. |
| T1112 Modify Registry |
MalwarePHOREAL | PHOREAL is capable of manipulating the Registry. |
| T1112 Modify Registry |
MalwareBitPaymer | BitPaymer can set values in the Registry to help in execution. |
| T1112 Modify Registry |
MalwareBACKSPACE | BACKSPACE is capable of deleting Registry keys, sub-keys, and values on a victim system. |
| T1112 Modify Registry |
MalwareADVSTORESHELL | ADVSTORESHELL is capable of setting and deleting Registry values. |
| T1112 Modify Registry |
MalwareWarzoneRAT | WarzoneRAT can create `HKCU\Software\Classes\Folder\shell\open\command` as a new registry key during privilege escalation. |
| T1112 Modify Registry |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can add, modify, and/or delete registry keys. It has changed the proxy configuration of a victim system by modifying the |
| T1112 Modify Registry |
ToolNPPSPY | NPPSPY modifies the Registry to record the malicious listener for output from the Winlogon process. |
| T1112 Modify Registry |
ToolSILENTTRINITY | SILENTTRINITY can modify registry keys, including to enable or disable Remote Desktop Protocol (RDP). |
| T1112 Modify Registry |
ToolAADInternals | AADInternals can modify registry keys as part of setting a new pass-through authentication agent. |
| T1112 Modify Registry |
ToolPcShare | PcShare can delete its persistence mechanisms from the registry. |
| T1112 Modify Registry |
ToolCSPY Downloader | CSPY Downloader can write to the Registry under the |
| T1112 Modify Registry |
ToolRemcos | Remcos has full control of the Registry, including the ability to modify it. |
| T1112 Modify Registry |
ToolCrackMapExec | CrackMapExec can create a registry key using wdigest. |
| T1112 Modify Registry |
ToolReg | Reg may be used to interact with and modify the Windows Registry of a local or remote system at the command-line interface. |
| T1112 Modify Registry |
ToolQuasarRAT | QuasarRAT has a command to edit the Registry on the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.