Query Registry using Built-in Tools

This rule identifies the execution of commands that can be used to query the Windows Registry. Adversaries may query the registry to gain situational awareness about the host, like installed security software, programs and settings.

Rule type: eql
Rule indices:

  • logs-endpoint.events.process-*

Rule Severity: low
Risk Score: 21
Runs every:
Searches indices from: now-9m
Maximum alerts per execution: 100
References:

Tags:

  • Domain: Endpoint
  • OS: Windows
  • Use Case: Threat Detection
  • Tactic: Discovery
  • Rule Type: BBR
  • Data Source: Elastic Defend
  • Rule Type: Event Correlation (EQL)
  • Platform: Windows

Version: 109
Rule authors:

  • Elastic

Rule license: Elastic License v2

process where host.os.type == "windows" and event.type == "start" and
  (
    (process.name : "reg.exe" and process.args : "query") or
    (
      process.name : ("powershell.exe", "powershell_ise.exe", "pwsh.exe") and
      process.args : ("get-childitem", "gci", "dir", "ls", "get-item", "gi", "get-itemproperty", "gp") and
      process.args : ("hkcu", "hkey_current_user", "hkey_local_machine", "hklm", "registry::*")
    )
  ) and
  not process.command_line : (
    "C:\\Windows\\system32\\reg.exe  query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64",
    "reg  query \"HKLM\\Software\\WOW6432Node\\Npcap\" /ve  "
  )
		

Framework: MITRE ATT&CK