Query Registry T1012

Tactic: Discovery

Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.

Events covered

7 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 34 rules share fields, values, and exclusions.

Fields filtered most (30 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventID15eq 154663, 4104, 4688, 1, 4103
Channel9eq 9, in 9
CommandLine9contains 7, ends_with 2, in 1, is_not_null 1, match 1 -e , \sam, \security, -exec bypass -enc jgag, restore
eventtype9eq 9
TargetFilename8contains 4, ends_with 4:\\windows\\system32\\drivers\\etc\\hosts, \\appdata\\local\\google\\chrome\\user..., \\appdata\\local\\google\\chrome\\user data\\default\\login data, \\appdata\\local\\google\\chrome\\user data\\local state, \\discord\\local storage\\leveldb
OriginalFileName7eq 7reg.exe, regedit.exe, pchunter.exe, wmic.exe
process_name6eq 3, contains 2, ne 1microsoft.identity.health.adfs.diagnosticsagent.exe, microsoft.identity.health.adfs.insightsservice.exe, microsoft.identity.health.adfs.monitoringagent.startup.exe, reg.exe, *\\discord.exe
Image5ends_with 5\regedit.exe, \pchunter32.exe, \pchunter64.exe, \reg.exe, \wmic.exe
ObjectName5ends_with 2, eq 2, contains 1, starts_with 1\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\CloudDomai..., \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Cryptograp..., \SAM, \registry\machine\software\microsoft\adhealthagent, \registry\machine\software\microsoft\microsoft...
ObjectType5eq 5key, Key
ScriptBlockText3contains 1, eq 1, in 1, regex_match 1(get-item|gci|get-childitem).{1,64}-path.{1,64}\\(current..., .getgporeport(), ::getipglobalproperties(), ::getprocesses, get-itemproperty
event.category2eq 2process
event.type2eq 2start
All_Risk.analyticstories1contains 1windows post-exploitation
CallerProcessName1ends_with 1\checkadmin.exe

Top indicator values (265 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventIDeq
4663
1035
EventIDeq
4104
2269
EventIDeq
4688
2317
ObjectTypeeq
key
45
OriginalFileNameeq
reg.exe
343
OriginalFileNameeq
regedit.exe
26
process_nameeq
reg.exe
327
CommandLinecontains
-e
217
CommandLinecontains
hkey_local_machine
22
CommandLinecontains
hklm
24
CommandLinecontains
-exec bypass -enc jgag
1
CommandLinecontains
restore
1
CommandLinecontains
(new-object system.net.webclient).uploadfile('http
1
CommandLinecontains
.hta
16
CommandLinecontains
/tn win32times /f
1
CommandLinecontains
\c$\windows\system32\devmgr.dll
1
CommandLinecontains
call
18
CommandLineends_with
\sam
2
CommandLineends_with
\security
2
CommandLineends_with
\system
2
Imageends_with
\regedit.exe
28
event.categoryeq
process
2142
event.typeeq
start
21078
process_namecontains
microsoft.identity.health.adfs.diagnosticsagent.exe
2
process_namecontains
microsoft.identity.health.adfs.insightsservice.exe
2
process_namecontains
microsoft.identity.health.adfs.monitoringagent.startup.exe
2
process_namecontains
microsoft.identity.health.adfs.pshsurrogate.exe
2
process_namecontains
microsoft.identity.health.common.clients.resourcemonitor.exe
2
All_Risk.analyticstoriescontains
windows post-exploitation
1
CallerProcessNameends_with
\checkadmin.exe
1

Exclusions (49 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process_namein
*:\\windows\\explorer.exe
4
process_namein
*\\appdata\\local\\google\\chrome beta\\application\\chrome.exe
3
process_namein
*\\appdata\\local\\google\\chrome dev\\application\\chrome.exe
3
process_namein
*\\appdata\\local\\google\\chrome sxs\\application\\chrome.exe
3
process_namein
*\\appdata\\local\\google\\chrome unstable\\application\\chrome.exe
3
process_namein
*\\appdata\\local\\google\\chrome\\application\\chrome.exe
3
process_namein
*:\\windows\\system32\\*
2
process_namein
*:\\windows\\syswow64\\*
2
process_namecontains
microsoft.identity.health.adfs.diagnosticsagent.exe
2
process_namecontains
microsoft.identity.health.adfs.insightsservice.exe
2
process_namecontains
microsoft.identity.health.adfs.monitoringagent.startup.exe
2
process_namecontains
microsoft.identity.health.adfs.pshsurrogate.exe
2
process_namecontains
microsoft.identity.health.common.clients.resourcemonitor.exe
2
CommandLinecontains
hkey_local_machine
1
CommandLinecontains
hklm
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Windows

Domain: Endpoint

Sigma 13 rules

Elastic 3 rules

Splunk 17 rules

Kusto 1 rule