Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · defense-impairment, Persistence

T1112 Modify Registry

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility [Reg](https://attack.mitre.org/software/S0075) may be used for local or remote…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Showing 25 of 40.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.