Cross-source coverage
T1012 / ATT&CK
Query Registry
48 rules · 47 families across 6 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from Query Registry during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
- Tactics
- Discovery
- Platforms
- Windows
- Telemetry
-
WinEventLog:SysmonWinEventLog:PowerShell
How MITRE says to detect it DET0209
Detection of Registry Query for Environmental Discovery
Windows Analytic 0589
Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=13, 14WinEventLog:PowerShellEventCode=4103, 4104, 4105, 4106
SigmaHQ/sigma
14 rules| Detection | Severity | Format |
|---|---|---|
| Exports Critical Registry Keys To a File | High | Sigma |
| HackTool - PCHunter Execution | High | Sigma |
| Operation Wocao Activity | High | Sigma |
| Operation Wocao Activity - Security | High | Sigma |
| Potential Baby Shark Malware Activity | High | Sigma |
| SAM Registry Hive Handle Request | High | Sigma |
| SysKey Registry Keys Access | High | Sigma |
| Azure AD Health Monitoring Agent Registry Keys Access | Medium | Sigma |
| Azure AD Health Service Agents Registry Keys Access | Medium | Sigma |
| Potential Configuration And Service Reconnaissance Via Reg.EXE | Medium | Sigma |
+ 4 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
13 rules| Detection | Severity | Format |
|---|---|---|
| Windows Credential Access From Browser Password Store | Undefined | SPL |
| Windows Credentials from Password Stores Chrome Extension Access | Undefined | SPL |
| Windows Credentials from Password Stores Chrome LocalState Access | Undefined | SPL |
| Windows Credentials from Password Stores Chrome Login Data Access | Undefined | SPL |
| Windows Hosts File Access | Undefined | SPL |
| Windows Non Discord App Access Discord LevelDB | Undefined | SPL |
| Windows Post Exploitation Risk Behavior | Undefined | SPL |
| Windows Product Key Registry Query | Undefined | SPL |
| Windows Query Registry Browser List Application | Undefined | SPL |
| Windows Query Registry UnInstall Program List | Undefined | SPL |
+ 3 more from splunk/security_content → showing the 10 highest-severity
socfortress/Wazuh-Rules
9 rules · 8 families| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · PowerShell COM Object Enumeration (T1012) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell Registry Enumeration (T1012) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Query Registry (T1012) 2 variants | High | Wazuh XML |
| Sysmon - Event 1: Process creation · reg.exe AlwaysInstallElevated query (T1012) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · reg.exe generic query (T1012) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · reg.exe SIL CollectionState query (T1012) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · reg.exe SystemStartOptions query (T1012) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Query Registry (T1012) 2 variants | Low | Wazuh XML |
| Sysmon - Event 3: Network connection by · Query Registry (T1012) | Low | Wazuh XML |
chronicle/detection-rules
8 rules| Detection | Severity | Format |
|---|---|---|
| apt28_zekapabzebrocycannon_implant_sysmonfirewallproxy_part2 | Undefined | YARA-L |
| apt28_zekapab_zebrocy_implant__sysmon_firewall_proxy | Undefined | YARA-L |
| a_variant_of_data_stealer_trojan_activity | Undefined | YARA-L |
| covid19_themed_malware_via_chm_file | Undefined | YARA-L |
| persistence_of_ryuk_ransomware | Undefined | YARA-L |
| poetrat_pythonrat_uses_covid19_lure | Undefined | YARA-L |
| registry_explorer_tool_detector | Undefined | YARA-L |
| ursnif_trojan_detection_cmd_obfuscation | Undefined | YARA-L |
Wazuh Core Ruleset
2 rules| Detection | Severity | Format |
|---|---|---|
| Powershell script queried registry value | Low | Wazuh XML |
| Powershell tampering software installation info on system registry | Low | Wazuh XML |
elastic/detection-rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Enumeration Command Spawned via WMIPrvSE | Low | Elastic TOML |
| Query Registry via reg.exe | Low | Elastic TOML |