A Windows OS hierarchical database that stores much of the information and settings for software programs, hardware devices, user preferences, and operating-system configurations[1]
Opening a Registry Key, typically to read the associated value (ex: Windows EID 4656)
Opening a Registry Key, typically to read the associated value (ex: Windows EID 4656)
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1003 | OS Credential Dumping | |
.002 | Security Account Manager | ||
.004 | LSA Secrets | ||
Enterprise | T1012 | Query Registry | |
Enterprise | T1614 | .001 | System Location Discovery: System Language Discovery |
Enterprise | T1552 | Unsecured Credentials | |
.002 | Credentials in Registry |
Initial construction of a new Registry Key (ex: Windows EID 4656 or Sysmon EID 12)
Initial construction of a new Registry Key (ex: Windows EID 4656 or Sysmon EID 12)
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1547 | Boot or Logon Autostart Execution | |
.001 | Registry Run Keys / Startup Folder | ||
.014 | Active Setup | ||
Enterprise | T1037 | Boot or Logon Initialization Scripts | |
.001 | Logon Script (Windows) | ||
Enterprise | T1176 | Browser Extensions | |
Enterprise | T1543 | Create or Modify System Process | |
.003 | Windows Service | ||
Enterprise | T1562 | .002 | Impair Defenses: Disable Windows Event Logging |
.009 | Impair Defenses: Safe Mode Boot | ||
Enterprise | T1112 | Modify Registry | |
Enterprise | T1137 | Office Application Startup | |
.001 | Office Template Macros | ||
.002 | Office Test | ||
.006 | Add-ins | ||
Enterprise | T1553 | Subvert Trust Controls | |
.004 | Install Root Certificate |
Removal of a Registry Key (ex: Windows EID 4658 or Sysmon EID 12)
Removal of a Registry Key (ex: Windows EID 4658 or Sysmon EID 12)
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1562 | Impair Defenses | |
.001 | Disable or Modify Tools | ||
Enterprise | T1070 | Indicator Removal on Host | |
Enterprise | T1112 | Modify Registry |
Changes made to a Registry Key and/or Key value (ex: Windows EID 4657 or Sysmon EID 13|14)
Changes made to a Registry Key and/or Key value (ex: Windows EID 4657 or Sysmon EID 13|14)