Modify Registry T1112

Tactics: Defense Impairment, Persistence

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Events covered

20 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 307 rules share fields, values, and exclusions.

Fields filtered most (70 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Details175eq 118, is_not_null 38, contains 15, starts_with 10, wildcard 7, ends_with 6, length_compare 5, in 3, is_null 2, match 1, ne 1, regex_match 10x00000001, 0, dword (0x00000001), 0x00000000, dword (0x00000000)
TargetObject137wildcard 54, ends_with 51, contains 34, eq 9, regex_match 5, starts_with 3, in 1, is_not_null 1, match 1h*\software\microsoft\windows\currentversion\run\*, hkey_users\*\environment\userinitmprlogonscript, hkey_users\*\software\microsoft\command processor\autorun, h*\software\microsoft\windows\currentversion\policies\exp..., hkey_users\*\software\microsoft\ctf\langbaraddin\*\filepath
registry_path68contains 33, ends_with 33, eq 1, in 1\\software\\microsoft\\windows\\currentversion\\policies\..., \\inprocserver32\\, *\\kingsoft\\antivirus\\kavreport\\*, *\\kingsoft\\antivirus\\ksetting\\*, *\\kingsoft\\antivirus\\windhunter\\*
registry_value_name58eq 51, in 6, ne 1, regex_match 1start, LmCompatibilityLevel, consentpromptbehavioradmin, debugger, disablearchivescanning
Image55ends_with 27, is_not_null 13, starts_with 12, contains 7, eq 7, wildcard 3, is_null 1, ne 1, regex_match 1\reg.exe, ?:\, \powershell.exe, \pwsh.exe, :\program files (x86)\microsoft office\
host.os.type43eq 43
EventType40eq 29, ne 9, in 2modification, deletion, start, modified, deleted
event.type38eq 35, in 3change, creation, start
CommandLine29contains 24, regex_match 7, ends_with 2 add , -a , -c , -e , /f
EventID29eq 28, in 14688, 1, 4104, 13, 4103
process_name21eq 14, is_not_null 2, regex_match 2, ends_with 1, in 1, wildcard 1cscript.exe, powershell.exe, mshta.exe, (?i)\x5cregini\.exe, cmd.exe
OriginalFileName15eq 15reg.exe, powershell.exe, pwsh.dll, regedit.exe, regini.exe
user.id9starts_with 6, ne 3S-1-12-, S-1-5-21, S-1-5-18
Type8eq 8
process.code_signature.exists8eq 8false

Top indicator values (1373 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
Detailseq
0x00000001
4061
Detailseq
dword (0x00000001)
2240
Detailseq
0
1718
Detailseq
0x00000000
1741
Detailseq
1
1420
Detailseq
dword (0x00000000)
1338
Detailseq
4
67
event.typeeq
change
3394
EventTypeeq
modification
1472
EventIDeq
4688
10317
EventIDeq
1
8241
EventIDeq
4104
6269
EventTypene
deletion
986
Imageends_with
\reg.exe
858
OriginalFileNameeq
reg.exe
843
TargetObjectwildcard
hkey_users\*\environment\userinitmprlogonscript
812
TargetObjectwildcard
hkey_users\*\software\microsoft\windows nt\currentversion\windows\load
812
TargetObjectwildcard
hkey_users\*\software\microsoft\windows nt\currentversion\winlogon\shell
812
TargetObjectwildcard
hkey_users\*\software\microsoft\command processor\autorun
711
TargetObjectwildcard
hkey_users\*\software\microsoft\ctf\langbaraddin\*\filepath
711
TargetObjectwildcard
hkey_users\*\software\microsoft\internet explorer\extensions\*\exec
711
TargetObjectwildcard
hkey_users\*\software\microsoft\windows\currentversion\policies\system\shell
711
TargetObjectwildcard
hkey_users\*\software\policies\microsoft\windows\system\scripts\logoff\script
711
TargetObjectwildcard
hkey_users\*\software\policies\microsoft\windows\system\scripts\logon\script
711
TargetObjectwildcard
hkey_users\*\software\policies\microsoft\windows\system\scripts\shutdown\script
711
TargetObjectwildcard
hkey_users\*\software\policies\microsoft\windows\system\scripts\startup\script
711
process.code_signature.existseq
false
8119
process.code_signature.trustedeq
false
7115
process_nameeq
powershell.exe
6184
process_nameeq
rundll32.exe
6126

Exclusions (647 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
13
user.ideq
s-1-5-18
13
user.ideq
s-1-5-19
7
user.ideq
s-1-5-20
6
Imagewildcard
?:\program files\*.exe
11
Imagewildcard
?:\windows\system32\svchost.exe
10
Imagewildcard
?:\program files (x86)\*.exe
9
Imagewildcard
?:\windows\system32\msiexec.exe
6
Imagewildcard
\device\harddiskvolume*\windows\system32\svchost.exe
5
Imagewildcard
?:\program files (x86)\*
4
Imageeq
?:\windows\system32\svchost.exe
6
Imageeq
?:\windows\system32\services.exe
3
Detailseq
(empty)
4
Imagestarts_with
c:\program files\
4
Imageends_with
\officeclicktorun.exe
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 98 rules

Elastic 93 rules

Splunk 107 rules

Kusto 1 rule

YARA-L 8 rules