Real-world descriptions of how a group, tool or campaign used a technique.
139 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1112 Modify Registry |
MalwareTrickBot | TrickBot can modify registry entries. |
| T1112 Modify Registry |
MalwareRCSession | RCSession can write its configuration file to the Registry. |
| T1112 Modify Registry |
MalwareSynAck | SynAck can manipulate Registry keys. |
| T1112 Modify Registry |
MalwareExaramel for Windows | Exaramel for Windows adds the configuration to the Registry in XML format. |
| T1112 Modify Registry |
MalwareAmadey | Amadey has overwritten registry keys for persistence. |
| T1112 Modify Registry |
MalwareOrz | Orz can perform Registry operations. |
| T1112 Modify Registry |
MalwareStuxnet | Stuxnet can create registry keys to load driver files. |
| T1112 Modify Registry |
MalwareKEYMARBLE | KEYMARBLE has a command to create Registry entries for storing data under |
| T1112 Modify Registry |
MalwareUrsnif | Ursnif has used Registry modifications as part of its installation routine. |
| T1112 Modify Registry |
MalwareThreatNeedle | ThreatNeedle can modify the Registry to save its configuration data as the following RC4-encrypted Registry key: `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`. |
| T1112 Modify Registry |
MalwareZeus Panda | Zeus Panda modifies several Registry keys under |
| T1112 Modify Registry |
MalwarePrestige | Prestige has the ability to register new registry keys for a new extension handler via `HKCR\.enc` and `HKCR\enc\shell\open\command`. |
| T1112 Modify Registry |
MalwareBankshot | Bankshot writes data into the Registry key |
| T1112 Modify Registry |
MalwarePLAINTEE | PLAINTEE uses |
| T1112 Modify Registry |
MalwareNETWIRE | NETWIRE can modify the Registry to store its configuration information. |
| T1112 Modify Registry |
MalwareTinyTurla | TinyTurla can set its configuration parameters in the Registry. |
| T1112 Modify Registry |
MalwareBOOKWORM | BOOKWORM has modified Registry key values as part of its created service `DeviceSync`. |
| T1112 Modify Registry |
MalwareHyperStack | HyperStack can add the name of its communication pipe to |
| T1112 Modify Registry |
MalwareGreyEnergy | GreyEnergy modifies conditions in the Registry and adds keys. |
| T1112 Modify Registry |
MalwareCrimson | Crimson can set a Registry key to determine how long it has been installed and possibly to indicate the version number. |
| T1112 Modify Registry |
MalwareTEARDROP | TEARDROP modified the Registry to create a Windows service for itself on a compromised host. |
| T1112 Modify Registry |
MalwareMafalda | Mafalda can manipulate the system registry on a compromised host. |
| T1112 Modify Registry |
MalwarePolyglotDuke | PolyglotDuke can write encrypted JSON configuration files to the Registry. |
| T1112 Modify Registry |
MalwareShrinkLocker | ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption. |
| T1112 Modify Registry |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies the victim Registry to allow for elevated execution. |
| T1112 Modify Registry |
MalwareHOPLIGHT | HOPLIGHT has modified Managed Object Format (MOF) files within the Registry to run specific commands and create persistence on the system. |
| T1112 Modify Registry |
MalwareWastedLocker | WastedLocker can modify registry values within the |
| T1112 Modify Registry |
MalwareRegDuke | RegDuke can create seemingly legitimate Registry key to store its encryption key. |
| T1112 Modify Registry |
MalwareInvisiMole | InvisiMole has a command to create, set, copy, or delete a specified Registry key or value. |
| T1112 Modify Registry |
MalwareNaid | Naid creates Registry entries that store information about a created service and point to a malicious DLL dropped to disk. |
| T1112 Modify Registry |
MalwareVolgmer | Volgmer modifies the Registry to store an encoded configuration file in |
| T1112 Modify Registry |
MalwareTRANSLATEXT | TRANSLATEXT has modified the following registry key to install itself as the value, granting permission to install specified extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist`. |
| T1112 Modify Registry |
MalwareRegin | Regin appears to have functionality to modify remote Registry information. |
| T1112 Modify Registry |
MalwareNeoichor | Neoichor has the ability to configure browser settings by modifying Registry entries under `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer`. |
| T1112 Modify Registry |
MalwareBlackCat | BlackCat has the ability to add the following registry key on compromised networks to maintain persistence: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \LanmanServer\Paramenters` |
| T1112 Modify Registry |
MalwarePowerShower | PowerShower has added a registry key so future powershell.exe instances are spawned off-screen by default, and has removed all registry entries that are left behind during the dropper process. |
| T1112 Modify Registry |
MalwareDarkComet | DarkComet adds a Registry value for its installation routine to the Registry Key |
| T1112 Modify Registry |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can use the Windows Registry Environment key to change the `%windir%` variable to point to `c:\Windows` to enable payload execution. |
| T1112 Modify Registry |
MalwarezwShell | zwShell can modify the Registry. |
| T1112 Modify Registry |
MalwareDCSrv | DCSrv has created Registry keys for persistence. |
| T1112 Modify Registry |
MalwareShimRat | ShimRat has registered two registry keys for shim databases. |
| T1112 Modify Registry |
MalwareAvaddon | Avaddon modifies several registry keys for persistence and UAC bypass. |
| T1112 Modify Registry |
MalwareConficker | Conficker adds keys to the Registry at |
| T1112 Modify Registry |
MalwareDarkTortilla | DarkTortilla has modified registry keys for persistence. |
| T1112 Modify Registry |
MalwareROKRAT | ROKRAT can modify the `HKEY_CURRENT_USER\Software\Microsoft\Office\` registry key so it can bypass the VB object model (VBOM) on a compromised host. |
| T1112 Modify Registry |
MalwareDarkWatchman | DarkWatchman can modify Registry values to store configuration strings, keylogger, and output of components. |
| T1112 Modify Registry |
MalwarePlugX | PlugX has a module to create, delete, or modify Registry keys. |
| T1112 Modify Registry |
MalwareBisonal | Bisonal has deleted Registry keys to clean up its prior activity. |
| T1112 Modify Registry |
MalwareNOOPLDR | NOOPLDR can store its payload in the Registry using a random hex string in `HKCU\SOFTWARE\Microsoft\COM3`. |
| T1112 Modify Registry |
MalwareExplosive | Explosive has a function to write itself to Registry values. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.