Skip to content

Latest commit

 

History

History
38 lines (31 loc) · 1.37 KB

MATCH-S00178.md

File metadata and controls

38 lines (31 loc) · 1.37 KB

Rules: Windows Query Registry

Description

Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.

Additional Details

Detail Value
Type Templated Match
Category Discovery
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Query Registry
Summary Expression Detected a query against the Windows Registry on the following host: {{device_hostname}}
Score/Severity Static: 1
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0007, _mitreAttackTechnique:T1012

Vendors and Products

Fields Used

Origin Field
Normalized Schema commandLine
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema listMatches
Normalized Schema user_username