kevmap

Techniques › T1012

T1012 Query Registry

discovery — Windows · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
14
Sigma rules tagged attack.t1012
0
KEV CVEs mapped here
<p>Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.</p><p>The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from Query Registry during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1012

Author: frack113 · 2023-07-02 · logsource: product=windows category=ps_script · 064060aa-09fb-4636-817f-020a32aa7e9e
Detects PowerShell scripts with potential registry reconnaissance capabilities. Adversaries may interact with the Windows registry to gather information about the system credentials, configuration, and installed software.
Techniques: T1012T1007
Author: Florian Roth (Nextron Systems), frack113 · 2019-12-20 (modified 2022-10-09) · logsource: product=windows category=process_creation · 1cfac73c-be78-4f9a-9b08-5bde0c3953ab
Detects activity mentioned in Operation Wocao report
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC · 2021-08-26 (modified 2022-10-09) · logsource: product=windows service=security · 1d2ab8ac-1a01-423b-9c39-001510eae8e8
This detection uses Windows security events to detect suspicious access attempts to the registry key values and sub-keys of Azure AD Health service agents (e.g AD FS). Information from AD Health service agents can be used to potentially abuse some of the features provided by those services in the cloud (e.g. Federation). This detection requires an access control entry (ACE) on the system access control list (SACL) of the following securable object: HKLM:\SOFTWARE\Microsoft\ADHealthAgent. Make sure you set the SACL to propagate to its sub-keys.
Techniques: T1012
Author: Florian Roth (Nextron Systems) · 2019-02-24 (modified 2023-03-08) · logsource: product=windows category=process_creation · 2b30fa36-3a18-402f-a22d-bf4ce2189f35
Detects activity that could be related to Baby Shark malware
Author: Teymur Kheirkhabarov, oscd.community · 2019-10-22 (modified 2023-12-15) · logsource: product=windows service=security · 68fcba0d-73a5-475e-a915-e8b4c576827e
Remote registry management using REG utility from non-admin workstation
Author: Florian Roth (Nextron Systems), frack113 · 2019-12-20 (modified 2022-11-27) · logsource: product=windows service=security · 74ad4314-482e-4c3e-b237-3f7ed3b9ca8d
Detects activity mentioned in Operation Wocao report
Author: Oddvar Moe, Sander Wiebing, oscd.community · 2020-10-12 (modified 2024-03-13) · logsource: product=windows category=process_creation · 82880171-b475-4201-b811-e9c826cd5eaa
Detects the export of a crital Registry key to a file.
Techniques: T1012
Author: Timur Zinniatullin, oscd.community · 2019-10-21 (modified 2023-02-05) · logsource: product=windows category=process_creation · 970007b7-ce32-49d0-a4a4-fbef016950bd
Detects the usage of "reg.exe" in order to query reconnaissance information from the registry. Adversaries may interact with the Windows registry to gather information about credentials, the system, configuration, and installed software.
Techniques: T1012T1007
Author: Roberto Rodriguez @Cyb3rWard0g · 2019-08-12 (modified 2021-11-27) · logsource: product=windows service=security · 9a4ff3b8-6187-4fd2-8e8b-e0eae1129495
Detects handle requests and access operations to specific registry keys to calculate the SysKey
Techniques: T1012
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-07-30 (modified 2026-06-19) · logsource: product=windows category=process_creation · a0e417e2-2fa1-40da-b6d2-e094cd5e1191
Detects the usage of wmic.exe to enumerate or read Windows registry via the WMI StdRegProv class read methods (EnumKey, EnumValues, GetStringValue, etc.). While registry reads are common, attackers may use this technique to perform reconnaissance and discover sensitive configuration values, credentials, or installed software. The use of WMI as an alternative to standard tools like reg.exe can indicate an attempt to evade detection focused on traditional registry query commands.
Techniques: T1047T1012
Author: Oddvar Moe, Sander Wiebing, oscd.community · 2020-10-07 (modified 2024-03-13) · logsource: product=windows category=process_creation · f0e53e89-8d22-46ea-9db5-9d4796ee2f8a
Detects the export of the target Registry key to a file.
Techniques: T1012
Author: Roberto Rodriguez @Cyb3rWard0g · 2019-08-12 (modified 2021-11-27) · logsource: product=windows service=security · f8748f2c-89dc-4d95-afb0-5a2dfdbad332
Detects handles requested to SAM registry hive
Techniques: T1012T1552.002
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali · 2022-10-10 (modified 2024-11-23) · logsource: product=windows category=process_creation · fca949cc-79ca-446e-8064-01aa7e52ece5
Detects suspicious use of PCHunter, a tool like Process Hacker to view and manipulate processes, kernel options and other low level stuff
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC · 2021-08-26 (modified 2022-10-09) · logsource: product=windows service=security · ff151c33-45fa-475d-af4f-c2f93571f4fe
This detection uses Windows security events to detect suspicious access attempts to the registry key of Azure AD Health monitoring agent. This detection requires an access control entry (ACE) on the system access control list (SACL) of the following securable object HKLM\SOFTWARE\Microsoft\Microsoft Online\Reporting\MonitoringAgent.
Techniques: T1012