Credentials in Registry

T1552.002

Sub-technique of T1552 Unsecured Credentials.View on attack.mitre.org

About this technique

Adversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information that can be used by the system or other programs. Adversaries may query the Registry looking for credentials and passwords that have been stored for use by other programs or services. Sometimes these credentials are used for automatic logons.

Example commands to find Registry keys related to password information:

* Local Machine Hive: reg query HKLM /f password /t REG_SZ /s
* Current User Hive: reg query HKCU /f password /t REG_SZ /s

Detection rules7

Rules on DetectionCode tagged with T1552.002.

Sigma4

RuleLevelLog source
Registry Export of Third-Party Credentialshighwindows / process_creation
SAM Registry Hive Handle Requesthighwindows / NULL
Enumeration for 3rd Party Creds From CLImediumwindows / process_creation
Enumeration for Credentials in Registrymediumwindows / process_creation

Splunk3

RuleTypeRiskData source
Add DefaultUser And Password In RegistryAnomalyNULLSysmon EventID 12, Sysmon EventID 13
Auto Admin Logon Registry EntryTTPNULLSysmon EventID 13
Windows Credentials in Registry Reg QueryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups3

Software7

Campaigns0

None recorded.

Procedure examples10

Groups3

Used byProcedure example
GroupAPT32

APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry.

GroupRedCurl

RedCurl used LaZagne to obtain passwords in the Registry.

GroupVOID MANTICORE

VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM.

Software7

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from the Registry.

MalwareIceApple

IceApple can harvest credentials from local and remote host registries.

ToolPowerSploit

PowerSploit has several modules that search the Windows Registry for stored credentials: Get-UnattendedInstallFile, Get-Webconfig, Get-ApplicationHost, Get-SiteListPassword, Get-CachedGPPPassword, and Get-RegistryAutoLogon.

ToolReg

Reg may be used to find credentials in the Windows Registry.

MalwareStrelaStealer

StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application.

MalwareTrickBot

TrickBot has retrieved PuTTY credentials by querying the Software\SimonTatham\Putty\Sessions registry key

MalwareValak

Valak can use the clientgrabber module to steal e-mail credentials from the Registry.

References1

  1. Pentestlab Stored Credentials Open source
    netbiosX. (2017, April 19). Stored Credentials. Retrieved April 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.