Real-world descriptions of how a group, tool or campaign used a technique.
99 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareSynAck | SynAck enumerates Registry keys associated with event logs. |
| T1012 Query Registry |
MalwareBumblebee | Bumblebee can check the Registry for specific keys. |
| T1012 Query Registry |
MalwareProxysvc | Proxysvc gathers product names from the Registry key: |
| T1012 Query Registry |
MalwareStuxnet | Stuxnet searches the Registry for indicators of security programs. |
| T1012 Query Registry |
MalwarePOWRUNER | POWRUNER may query the Registry by running |
| T1012 Query Registry |
MalwareUrsnif | Ursnif has used Reg to query the Registry for installed programs. |
| T1012 Query Registry |
MalwarePOWERSOURCE | POWERSOURCE queries Registry keys in preparation for setting Run keys to achieve persistence. |
| T1012 Query Registry |
MalwareZeus Panda | Zeus Panda checks for the existence of a Registry key and if it contains certain values. |
| T1012 Query Registry |
MalwareBankshot | Bankshot searches for certain Registry keys to be configured before executing the payload. |
| T1012 Query Registry |
MalwareBrave Prince | Brave Prince gathers information about the Registry. |
| T1012 Query Registry |
MalwareTinyTurla | TinyTurla can query the Registry for its configuration information. |
| T1012 Query Registry |
MalwareCrimson | Crimson can check the Registry for the presence of |
| T1012 Query Registry |
MalwareTEARDROP | TEARDROP checked that |
| T1012 Query Registry |
MalwareDUSTTRAP | DUSTTRAP can enumerate Registry items. |
| T1012 Query Registry |
MalwarePUBLOAD | PUBLOAD has queried Registry values to identify software using `reg query`. |
| T1012 Query Registry |
MalwareWoody RAT | Woody RAT can search registry keys to identify antivirus programs on an compromised host. |
| T1012 Query Registry |
MalwareMafalda | Mafalda can enumerate Registry keys with all subkeys and values. |
| T1012 Query Registry |
MalwareHOPLIGHT | A variant of HOPLIGHT hooks lsass.exe, and lsass.exe then checks the Registry for the data value 'rdpproto' under the key |
| T1012 Query Registry |
MalwareWastedLocker | WastedLocker checks for specific registry keys related to the |
| T1012 Query Registry |
MalwareInvisiMole | InvisiMole can enumerate Registry values, keys, and data. |
| T1012 Query Registry |
MalwareVolgmer | Volgmer checks the system for certain Registry keys. |
| T1012 Query Registry |
MalwareTRANSLATEXT | TRANSLATEXT has queried the following registry key to check for installed Chrome extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist `. |
| T1012 Query Registry |
MalwareFatDuke | FatDuke can get user agent strings for the default browser from |
| T1012 Query Registry |
MalwareLucifer | Lucifer can check for existing stratum cryptomining information in |
| T1012 Query Registry |
MalwareRising Sun | Rising Sun has identified the OS product name from a compromised host by searching the registry for `SOFTWARE\MICROSOFT\Windows NT\ CurrentVersion | ProductName`. |
| T1012 Query Registry |
MalwareROKRAT | ROKRAT can access the |
| T1012 Query Registry |
MalwareDarkWatchman | DarkWatchman can query the Registry to determine if it has already been installed on the system. |
| T1012 Query Registry |
MalwarePlugX | PlugX can enumerate and query for information contained within the Windows Registry. |
| T1012 Query Registry |
MalwareReaver | Reaver queries the Registry to determine the correct Startup path to use for persistence. |
| T1012 Query Registry |
MalwareBisonal | Bisonal has used the RegQueryValueExA function to retrieve proxy information in the Registry. |
| T1012 Query Registry |
MalwareEpic | Epic uses the |
| T1012 Query Registry |
MalwareClambling | Clambling has the ability to enumerate Registry keys, including |
| T1012 Query Registry |
MalwareSVCReady | SVCReady can search for the `HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System` Registry key to gather system information. |
| T1012 Query Registry |
MalwareCarbanak | Carbanak checks the Registry key |
| T1012 Query Registry |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can retrieve system information, such as CPU speed, from Registry keys. |
| T1012 Query Registry |
MalwareSaint Bot | Saint Bot has used `check_registry_keys` as part of its environmental checks. |
| T1012 Query Registry |
MalwareCharmPower | CharmPower has the ability to enumerate `Uninstall` registry values. |
| T1012 Query Registry |
MalwareMori | Mori can read data from the Registry including from `HKLM\Software\NFC\IPA` and |
| T1012 Query Registry |
MalwareQUADAGENT | QUADAGENT checks if a value exists within a Registry key in the HKCU hive whose name is the same as the scheduled task it has created. |
| T1012 Query Registry |
MalwareBendyBear | BendyBear can query the host's Registry key at |
| T1012 Query Registry |
MalwareUroburos | Uroburos can query the Registry, typically `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds`, to find the key and path to decrypt and load its kernel driver and kernel driver loader. |
| T1012 Query Registry |
Malwaregh0st RAT | gh0st RAT has checked for the existence of a Service key to determine if it has already been installed on the system. |
| T1012 Query Registry |
MalwareShamoon | Shamoon queries several Registry keys to identify hard disk partitions to overwrite. |
| T1012 Query Registry |
MalwareRedLine Stealer | RedLine Stealer can query the Windows Registry. |
| T1012 Query Registry |
MalwareStoneDrill | StoneDrill has looked in the registry to find the default browser path. |
| T1012 Query Registry |
MalwareAttor | Attor has opened the registry and performed query searches. |
| T1012 Query Registry |
MalwareLitePower | LitePower can query the Registry for keys added to execute COM hijacking. |
| T1012 Query Registry |
MalwareQUIETCANARY | QUIETCANARY has the ability to retrieve information from the Registry. |
| T1012 Query Registry |
MalwareDerusbi | Derusbi is capable of enumerating Registry keys and values. |
| T1012 Query Registry |
MalwareBlackByte Ransomware | BlackByte Ransomware enumerates the Registry, specifically the `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options` key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.