Query Registry

T1012

Technique.View on attack.mitre.org

About this technique

Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.

The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from Query Registry during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Detection rules24

Rules on DetectionCode tagged with T1012.

Sigma9

RuleLevelLog source
Exports Critical Registry Keys To a Filehighwindows / process_creation
HackTool - PCHunter Executionhighwindows / process_creation
SAM Registry Hive Handle Requesthighwindows / NULL
SysKey Registry Keys Accesshighwindows / NULL
Azure AD Health Monitoring Agent Registry Keys Accessmediumwindows / NULL
Azure AD Health Service Agents Registry Keys Accessmediumwindows / NULL
Potential Configuration And Service Reconnaissance Via Reg.EXEmediumwindows / process_creation
Registry Enumeration via WMI Stdregprovmediumwindows / process_creation
Exports Registry Key To a Filelowwindows / process_creation

Splunk15

RuleTypeRiskData source
Windows Credential Access From Browser Password StoreAnomalyNULLWindows Event Log Security 4663
Windows Credentials from Password Stores Chrome Extension AccessAnomalyNULLWindows Event Log Security 4663
Windows Credentials from Password Stores Chrome LocalState AccessAnomalyNULLWindows Event Log Security 4663
Windows Credentials from Password Stores Chrome Login Data AccessAnomalyNULLWindows Event Log Security 4663
Windows Hosts File AccessAnomalyNULLWindows Event Log Security 4663
Windows Modify Registry Reg RestoreHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Non Discord App Access Discord LevelDBAnomalyNULLWindows Event Log Security 4663
Windows Post Exploitation Risk BehaviorCorrelationNULL
Windows Product Key Registry QueryAnomalyNULLWindows Event Log Security 4663
Windows Query Registry Browser List ApplicationAnomalyNULLWindows Event Log Security 4663
Windows Query Registry Reg SaveHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Query Registry UnInstall Program ListAnomalyNULLWindows Event Log Security 4663
Windows Registry Entries Exported Via RegHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Registry Entries Restored Via RegHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Software Discovery Via PowerShellAnomalyNULLPowershell Script Block Logging 4104

Groups19

Software99

Show 75 more

Campaigns1

Procedure examples119

Groups19

Used byProcedure example
GroupAPT32

APT32's backdoor can query the Windows Registry to gather system information.

GroupAPT39

APT39 has used various strains of malware to query the Registry.

GroupAPT41

APT41 queried registry values to determine items such as configured RDP ports and network configurations.

GroupBlackByte

BlackByte queried registry values to determine system language settings.

GroupChimera

Chimera has queried Registry keys using reg query \\<host>\HKU\<SID>\SOFTWARE\Microsoft\Terminal Server Client\Servers and reg query \\<host>\HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Internet Settings.

GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines.

GroupDragonfly

Dragonfly has queried the Registry to identify victim information.

GroupFox Kitten

Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat.

View all 19 groups examples

Software99

Used byProcedure example
MalwareADVSTORESHELL

ADVSTORESHELL can enumerate registry keys.

MalwareAttor

Attor has opened the registry and performed query searches.

MalwareAzorult

Azorult can check for installed software on the system under the Registry key Software\Microsoft\Windows\CurrentVersion\Uninstall.

MalwareBabyShark

BabyShark has executed the reg query command for HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default.

MalwareBACKSPACE

BACKSPACE is capable of enumerating and making modifications to an infected system's Registry.

MalwareBankshot

Bankshot searches for certain Registry keys to be configured before executing the payload.

MalwareBazar

Bazar can query Windows\CurrentVersion\Uninstall for installed applications.

MalwareBendyBear

BendyBear can query the host's Registry key at HKEY_CURRENT_USER\Console\QuickEdit to retrieve data.

View all 99 software examples

Campaigns1

Used byProcedure example
CampaignOperation Wocao

During Operation Wocao, the threat actors executed `/c cd /d c:\windows\temp\ & reg query HKEY_CURRENT_USER\Software\<username>\PuTTY\Sessions\` to detect recent PuTTY sessions, likely to further lateral movement.

References1

  1. Wikipedia Windows Registry Open source
    Wikipedia. (n.d.). Windows Registry. Retrieved February 2, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.