Modify Registry

T1112

Technique.View on attack.mitre.org

About this technique

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API.

The Registry may be modified in order to hide configuration information or malicious payloads via Obfuscated Files or Information. The Registry may also be modified to impair defenses, such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory.

The Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system. Often Valid Accounts are required, along with access to the remote system's SMB/Windows Admin Shares for RPC communication.

Finally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via Reg or other utilities using the Win32 API. Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.

Detection rules164

Rules on DetectionCode tagged with T1112.

Sigma84

RuleLevelLog source
Registry Entries For Azorult Malwarecriticalwindows / registry_event
Blackbyte Ransomware Registryhighwindows / registry_set
Blue Mockingbird - Registryhighwindows / registry_set
Change the Fax Dllhighwindows / registry_set
Change User Account Associated with the FAX Servicehighwindows / registry_set
DHCP Callout DLL Installationhighwindows / registry_set
Disable Security Events Logging Adding Reg Key MiniNthighwindows / registry_event
Enable LM Hash Storagehighwindows / registry_set
Enable LM Hash Storage - ProcCreationhighwindows / process_creation
ETW Logging Disabled In .NET Processes - Registryhighwindows / NULL
ETW Logging Disabled In .NET Processes - Sysmon Registryhighwindows / registry_set
Imports Registry Key From an ADShighwindows / process_creation
Macro Enabled In A Potentially Suspicious Documenthighwindows / registry_set
NET NGenAssemblyUsageLog Registry Key Tamperhighwindows / registry_set
NetNTLM Downgrade Attackhighwindows / NULL

Splunk80

RuleTypeRiskData source
Disable Registry ToolTTPNULLSysmon EventID 13
Disable Security Logs Using MiniNt RegistryTTPNULLSysmon EventID 13
Disable Show Hidden FilesAnomalyNULLSysmon EventID 13
Disable Windows App HotkeysTTPNULLSysmon EventID 13
Disabling CMD ApplicationTTPNULLSysmon EventID 13
Disabling ControlPanelTTPNULLSysmon EventID 13
Disabling NoRun Windows AppTTPNULLSysmon EventID 13
Enable WDigest UseLogonCredential RegistryTTPNULLSysmon EventID 13
FodHelper UAC BypassTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Malicious InProcServer32 ModificationTTPNULLSysmon EventID 12, Sysmon EventID 13
Remcos client registry install entryTTPNULLSysmon EventID 12, Sysmon EventID 13
Revil Registry EntryTTPNULLSysmon EventID 12, Sysmon EventID 13
Rundll32 Shimcache FlushTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Reg exe ProcessAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Anomalous Registry Value Length in Environment KeyAnomalyNULLSysmon EventID 13

Groups29

Show 5 more

Software139

Show 115 more

Campaigns5

Procedure examples173

Groups29

Used byProcedure example
GroupAPT19

APT19 uses a Port 22 malware variant to modify several Registry keys.

GroupAPT32

APT32's backdoor has modified the Windows Registry to store the backdoor's configuration.

GroupAPT38

APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys.

GroupAPT41

APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.

GroupAPT42

APT42 has modified Registry keys to maintain persistence.

GroupAquatic Panda

Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP.

GroupBlackByte

BlackByte performed Registry modifications to escalate privileges and disable security tools.

GroupBlue Mockingbird

Blue Mockingbird has used Windows Registry modifications to specify a DLL payload.

View all 29 groups examples

Software139

Used byProcedure example
ToolAADInternals

AADInternals can modify registry keys as part of setting a new pass-through authentication agent.

MalwareADVSTORESHELL

ADVSTORESHELL is capable of setting and deleting Registry values.

MalwareAgent Tesla

Agent Tesla can achieve persistence by modifying Registry key entries.

MalwareAmadey

Amadey has overwritten registry keys for persistence.

MalwareAttor

Attor's dispatcher can modify the Run registry key.

MalwareAvaddon

Avaddon modifies several registry keys for persistence and UAC bypass.

MalwareBACKSPACE

BACKSPACE is capable of deleting Registry keys, sub-keys, and values on a victim system.

MalwareBADCALL

BADCALL modifies the firewall Registry key SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfileGloballyOpenPorts\\List.

View all 139 software examples

Campaigns5

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching `rundll32.exe`, which in-turn launches the malware and communicates with C2 servers over the Internet. .

CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry.

CampaignOperation Honeybee

During Operation Honeybee, the threat actors used batch files that modified registry keys.

CampaignOperation Wocao

During Operation Wocao, the threat actors enabled Wdigest by changing the `HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest` registry value from 0 (disabled) to 1 (enabled).

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, disabled security services via Registry modifications.

References10

  1. Avaddon Ransomware 2021 Open source
    Javier Yuste and Sergio Pastrana. (2021). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved March 24, 2025.
  2. CISA LockBit 2023 Open source
    CISA. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved March 24, 2025.
  3. CISA Russian Gov Critical Infra 2018 Open source
    CISA. (2018, March 16). Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved March 24, 2025.
  4. Microsoft BlackCat Jun 2022 Open source
    Microsoft Defender Threat Intelligence. (2022, June 13). The many lives of BlackCat ransomware. Retrieved December 20, 2022.
  5. Microsoft Reg Open source
    Microsoft. (2012, April 17). Reg. Retrieved May 1, 2015.
  6. Microsoft Reghide NOV 2006 Open source
    Russinovich, M. & Sharkey, K. (2006, January 10). Reghide. Retrieved August 9, 2018.
  7. Microsoft Remote Open source
    Microsoft. (n.d.). Enable the Remote Registry Service. Retrieved May 1, 2015.
  8. SpectorOps Hiding Reg Jul 2017 Open source
    Reitz, B. (2017, July 14). Hiding Registry keys with PSReflect. Retrieved August 9, 2018.
  9. TrendMicro POWELIKS AUG 2014 Open source
    Santos, R. (2014, August 1). POWELIKS: Malware Hides In Windows Registry. Retrieved August 9, 2018.
  10. Unit42 BabyShark Feb 2019 Open source
    Unit 42. (2019, February 22). New BabyShark Malware Targets U.S. National Security Think Tanks. Retrieved October 7, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.