Cross-source coverage
T1112 / ATT&CK
Modify Registry
311 rules · 307 families across 8 sources.
23 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API.
The Registry may be modified in order to hide configuration information or malicious payloads via Obfuscated Files or Information. The Registry may also be modified to impair defenses, such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory.
The Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system. Often Valid Accounts are required, along with access to the remote system's SMB/Windows Admin Shares for RPC communication.
Finally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via Reg or other utilities using the Win32 API. Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.
- Tactics
- Defense Impairment · Persistence
- Platforms
- Windows
- Telemetry
-
WinEventLog:Sysmon
How MITRE says to detect it DET0280
Behavior-Based Registry Modification Detection on Windows
Windows Analytic 0781
Behavior chain involving abnormal registry modifications via CLI, PowerShell, WMI, or direct API calls, especially targeting persistence, privilege escalation, or defense evasion keys, potentially followed by service restart or process execution. Such as editing Notify/Userinit/Startup keys, or disabling SafeDllSearchMode.
WinEventLog:SysmonEventCode=13, 14WinEventLog:SysmonEventCode=1
SigmaHQ/sigma
96 rules| Detection | Severity | Format |
|---|---|---|
| FlowCloud Registry Markers | Critical | Sigma |
| OceanLotus Registry Activity | Critical | Sigma |
| OilRig APT Activity | Critical | Sigma |
| OilRig APT Registry Persistence | Critical | Sigma |
| OilRig APT Schedule Task Persistence - Security | Critical | Sigma |
| OilRig APT Schedule Task Persistence - System | Critical | Sigma |
| Registry Entries For Azorult Malware | Critical | Sigma |
| Blackbyte Ransomware Registry | High | Sigma |
| Blue Mockingbird | High | Sigma |
| Blue Mockingbird - Registry | High | Sigma |
+ 86 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
79 rules| Detection | Severity | Format |
|---|---|---|
| Disable Registry Tool | Undefined | SPL |
| Disable Security Logs Using MiniNt Registry | Undefined | SPL |
| Disable Show Hidden Files | Undefined | SPL |
| Disable Windows App Hotkeys | Undefined | SPL |
| Disabling CMD Application | Undefined | SPL |
| Disabling ControlPanel | Undefined | SPL |
| Disabling NoRun Windows App | Undefined | SPL |
| Enable WDigest UseLogonCredential Registry | Undefined | SPL |
| FodHelper UAC Bypass | Undefined | SPL |
| Malicious InProcServer32 Modification | Undefined | SPL |
+ 69 more from splunk/security_content → showing the 10 highest-severity
elastic/protections-artifacts
49 rules| Detection | Severity | Format |
|---|---|---|
| AllowProtectedRenames Registry Modification | Undefined | Elastic TOML |
| Attempt to Disable Driver via HVCIDisallowedImages | Undefined | Elastic TOML |
| Attempt to Disable Windows Driver Blocklist via Registry | Undefined | Elastic TOML |
| Attempt to Hide Files via Registry Modification | Undefined | Elastic TOML |
| Browser Native Messaging Registry Modification | Undefined | Elastic TOML |
| COM to .NET Redirection via Registry | Undefined | Elastic TOML |
| CrashDump Disabled via Registry Modification | Undefined | Elastic TOML |
| Defense Evasion via Registry Modification | Undefined | Elastic TOML |
| Disabling Hypervisor-protected Code Integrity via Registry | Undefined | Elastic TOML |
| Dual Persistence via Startup and Scheduled Task | Undefined | Elastic TOML |
+ 39 more from elastic/protections-artifacts → showing the 10 highest-severity
elastic/detection-rules
39 rules| Detection | Severity | Format |
|---|---|---|
| Disabling Lsa Protection via Registry Modification | High | Elastic TOML |
| Modification of AmsiEnable Registry Key | High | Elastic TOML |
| Modification of WDigest Security Provider | High | Elastic TOML |
| Outlook Home Page Registry Modification | High | Elastic TOML |
| Persistence via Hidden Run Key Detected | High | Elastic TOML |
| Privilege Escalation via Windir Environment Variable | High | Elastic TOML |
| Suspicious ImagePath Service Creation | High | Elastic TOML |
| Suspicious Print Spooler Point and Print DLL | High | Elastic TOML |
| Suspicious Startup Shell Folder Modification | High | Elastic TOML |
| Code Signing Policy Modification Through Registry | Medium | Elastic TOML |
+ 29 more from elastic/detection-rules → showing the 10 highest-severity
socfortress/Wazuh-Rules
19 rules · 16 families| Detection | Severity | Format |
|---|---|---|
| Chafer Activity 2 variants | Critical | Wazuh XML |
| Chafer Activity 2 variants | Critical | Wazuh XML |
| Sysmon - Event 1: Process creation · Disable Security Notifications (T1112) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Disable Windows Task Manager via registry (T1112) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Load malware via App Paths registry (T1112) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Registry modification via regini.exe (T1112) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Registry modification via regsvr32 (T1112) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Registry modified via cmd.exe (T1112) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Registry modified via PowerShell Set-ItemProperty (T1112) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Registry modified via reg.exe (T1112) | High | Wazuh XML |
+ 9 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
Wazuh Core Ruleset
17 rules+ 7 more from Wazuh Core Ruleset → showing the 10 highest-severity
chronicle/detection-rules
8 rules| Detection | Severity | Format |
|---|---|---|
| blackbyte_ransomware_registry | High | YARA-L |
| potential_tampering_with_rdp_related_registry_keys_via_reg_exe | High | YARA-L |
| rdp_sensitive_settings_changed | High | YARA-L |
| restrictedadminmode_registry_value_tampering | High | YARA-L |
| shimcache_flush | High | YARA-L |
| wdigest_enable_uselogoncredential | High | YARA-L |
| disable_internal_tools_or_feature_in_registry | Medium | YARA-L |
| rdp_sensitive_settings_changed_to_zero | Medium | YARA-L |
Azure/Azure-Sentinel
4 rules| Detection | Severity | Format |
|---|---|---|
| shimcache-flushed | Undefined | KQL |
| suspicious-base64-encoded-registry-keys | Undefined | KQL |
| suspicious-command-interpreters-added-to-registry | Undefined | KQL |
| suspicious-keywords-in-registry | Undefined | KQL |