Cross-source coverage

T1012 / ATT&CK

Query Registry

48 rules · 47 families across 6 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.

The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from Query Registry during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Tactics
Discovery
Platforms
Windows
Telemetry
WinEventLog:SysmonWinEventLog:PowerShell

How MITRE says to detect it DET0209

Detection of Registry Query for Environmental Discovery

Windows Analytic 0589

Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=13, 14
  • WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106

SigmaHQ/sigma

14 rules
Detection Severity Format
Exports Critical Registry Keys To a File High Sigma
HackTool - PCHunter Execution High Sigma
Operation Wocao Activity High Sigma
Operation Wocao Activity - Security High Sigma
Potential Baby Shark Malware Activity High Sigma
SAM Registry Hive Handle Request High Sigma
SysKey Registry Keys Access High Sigma
Azure AD Health Monitoring Agent Registry Keys Access Medium Sigma
Azure AD Health Service Agents Registry Keys Access Medium Sigma
Potential Configuration And Service Reconnaissance Via Reg.EXE Medium Sigma

+ 4 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

13 rules
Detection Severity Format
Windows Credential Access From Browser Password Store Undefined SPL
Windows Credentials from Password Stores Chrome Extension Access Undefined SPL
Windows Credentials from Password Stores Chrome LocalState Access Undefined SPL
Windows Credentials from Password Stores Chrome Login Data Access Undefined SPL
Windows Hosts File Access Undefined SPL
Windows Non Discord App Access Discord LevelDB Undefined SPL
Windows Post Exploitation Risk Behavior Undefined SPL
Windows Product Key Registry Query Undefined SPL
Windows Query Registry Browser List Application Undefined SPL
Windows Query Registry UnInstall Program List Undefined SPL

+ 3 more from splunk/security_content → showing the 10 highest-severity

socfortress/Wazuh-Rules

9 rules · 8 families
Detection Severity Format
Sysmon - Event 1: Process creation · PowerShell COM Object Enumeration (T1012) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell Registry Enumeration (T1012) High Wazuh XML
Sysmon - Event 1: Process creation · Query Registry (T1012) 2 variants High Wazuh XML
Sysmon - Event 1: Process creation · reg.exe AlwaysInstallElevated query (T1012) High Wazuh XML
Sysmon - Event 1: Process creation · reg.exe generic query (T1012) High Wazuh XML
Sysmon - Event 1: Process creation · reg.exe SIL CollectionState query (T1012) High Wazuh XML
Sysmon - Event 1: Process creation · reg.exe SystemStartOptions query (T1012) High Wazuh XML
Sysmon - Event 1: Process creation · Query Registry (T1012) 2 variants Low Wazuh XML
Sysmon - Event 3: Network connection by · Query Registry (T1012) Low Wazuh XML

chronicle/detection-rules

8 rules
Detection Severity Format
apt28_zekapabzebrocycannon_implant_sysmonfirewallproxy_part2 Undefined YARA-L
apt28_zekapab_zebrocy_implant__sysmon_firewall_proxy Undefined YARA-L
a_variant_of_data_stealer_trojan_activity Undefined YARA-L
covid19_themed_malware_via_chm_file Undefined YARA-L
persistence_of_ryuk_ransomware Undefined YARA-L
poetrat_pythonrat_uses_covid19_lure Undefined YARA-L
registry_explorer_tool_detector Undefined YARA-L
ursnif_trojan_detection_cmd_obfuscation Undefined YARA-L

Wazuh Core Ruleset

2 rules
Detection Severity Format
Powershell script queried registry value Low Wazuh XML
Powershell tampering software installation info on system registry Low Wazuh XML

elastic/detection-rules

2 rules
Detection Severity Format
Enumeration Command Spawned via WMIPrvSE Low Elastic TOML
Query Registry via reg.exe Low Elastic TOML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.