Loading the current evidence view. Navigation and account controls remain available.
ATT&CK knowledge
Loading the current evidence view. Navigation and account controls remain available.
Tactics: discovery
19
known groups
99
software
365
corpus matches
about
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from Query Registry during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
used by actors
19 known groups
corpus indicators tagged T1012
365 carry this technique
A shared-technique signal for hunting: each row resolves to its own verdict. Not attribution to any one group.
software
99 malware & tools implement this
showing top 30 by severity of 365