A Windows OS hierarchical database that stores much of the information and settings for software programs, hardware devices, user preferences, and operating-system configurations[1]
Opening a Registry Key, typically to read the associated value (ex: Windows EID 4656)
Opening a Registry Key, typically to read the associated value (ex: Windows EID 4656)
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1003 | OS Credential Dumping | |
| .002 | Security Account Manager | ||
| .004 | LSA Secrets | ||
| Enterprise | T1012 | Query Registry | |
| Enterprise | T1614 | .001 | System Location Discovery: System Language Discovery |
| Enterprise | T1552 | Unsecured Credentials | |
| .002 | Credentials in Registry | ||
Initial construction of a new Registry Key (ex: Windows EID 4656 or Sysmon EID 12)
Initial construction of a new Registry Key (ex: Windows EID 4656 or Sysmon EID 12)
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1547 | Boot or Logon Autostart Execution | |
| .001 | Registry Run Keys / Startup Folder | ||
| .014 | Active Setup | ||
| Enterprise | T1037 | Boot or Logon Initialization Scripts | |
| .001 | Logon Script (Windows) | ||
| Enterprise | T1176 | Browser Extensions | |
| Enterprise | T1543 | Create or Modify System Process | |
| .003 | Windows Service | ||
| Enterprise | T1562 | .002 | Impair Defenses: Disable Windows Event Logging |
| .009 | Impair Defenses: Safe Mode Boot | ||
| Enterprise | T1112 | Modify Registry | |
| Enterprise | T1137 | Office Application Startup | |
| .001 | Office Template Macros | ||
| .002 | Office Test | ||
| .006 | Add-ins | ||
| Enterprise | T1553 | Subvert Trust Controls | |
| .004 | Install Root Certificate | ||
Removal of a Registry Key (ex: Windows EID 4658 or Sysmon EID 12)
Removal of a Registry Key (ex: Windows EID 4658 or Sysmon EID 12)
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1562 | Impair Defenses | |
| .001 | Disable or Modify Tools | ||
| Enterprise | T1070 | Indicator Removal on Host | |
| Enterprise | T1112 | Modify Registry | |
Changes made to a Registry Key and/or Key value (ex: Windows EID 4657 or Sysmon EID 13|14)
Changes made to a Registry Key and/or Key value (ex: Windows EID 4657 or Sysmon EID 13|14)