AN0589
Analytic 0589
Windows
Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings.
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=13, 14
WinEventLog:PowerShell
EventCode=4103, 4104, 4105, 4106
[TargetRegistryPath]
Focus detection on registry hives or keys likely to reveal environment info (e.g., HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion).
[ParentProcess]
May tune for suspicious parent processes such as cmd.exe, wscript.exe, or mshta.exe.
[TimeWindow]
Controls how closely registry access must follow process creation for correlation.