Query Registry using Built-in Tools
This rule identifies the execution of commands that can be used to query the Windows Registry. Adversaries may query the registry to gain situational awareness about the host, like installed security software, programs and settings.
Rule type: eql
Rule indices:
- logs-endpoint.events.process-*
Rule Severity: low
Risk Score: 21
Runs every:
Searches indices from: now-9m
Maximum alerts per execution: 100
References:
Tags:
- Domain: Endpoint
- OS: Windows
- Use Case: Threat Detection
- Tactic: Discovery
- Rule Type: BBR
- Data Source: Elastic Defend
- Rule Type: Event Correlation (EQL)
- Platform: Windows
Version: 109
Rule authors:
- Elastic
Rule license: Elastic License v2
process where host.os.type == "windows" and event.type == "start" and
(
(process.name : "reg.exe" and process.args : "query") or
(
process.name : ("powershell.exe", "powershell_ise.exe", "pwsh.exe") and
process.args : ("get-childitem", "gci", "dir", "ls", "get-item", "gi", "get-itemproperty", "gp") and
process.args : ("hkcu", "hkey_current_user", "hkey_local_machine", "hklm", "registry::*")
)
) and
not process.command_line : (
"C:\\Windows\\system32\\reg.exe query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64",
"reg query \"HKLM\\Software\\WOW6432Node\\Npcap\" /ve "
)
Framework: MITRE ATT&CK
Tactic:
- Name: Discovery
- Id: TA0007
- Reference URL: https://attack.mitre.org/tactics/TA0007/
Technique:
- Name: Query Registry
- Id: T1012
- Reference URL: https://attack.mitre.org/techniques/T1012/