Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0250 — Detect Credential Discovery via Windows Registry Enumeration
DET0250

Detect Credential Discovery via Windows Registry Enumeration

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0694 Analytic 0694
Windows

Defenders observe command-line executions or API-based registry reads targeting sensitive paths like HKLM or HKCU with keyword filters such as 'password', 'cred', or 'logon'. Typically performed by Reg.exe, PowerShell, custom binaries, or offensive tools such as Cobalt Strike. Correlation with process ancestry and command-line arguments indicates suspicious credential discovery activity.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=13, 14 EDR:hunting Behavioral rule for registry enumeration under credential-related paths
[KeywordMatch] List of strings searched in registry queries (e.g., password, credential, login). May need to expand for localized OS or app-specific terms.
[ParentProcessFilter] Parent process used for registry access. Can tune for suspicious ancestry (e.g., cmd.exe > reg.exe vs. services.exe > reg.exe).
[TimeWindow] Time-based correlation window for detecting chained activity between registry reads and subsequent credential use or exfiltration.
[RegistryHiveScope] HKLM vs. HKCU vs. others. May limit scope to user or system context depending on risk appetite.

Detected Techniques

1

Details

MITRE ID
DET0250
STIX ID
x-mitre-detection-strategy--6c9e1f65-7d75-4091-b97d-e5f88ed12812
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.