Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0209 — Detection of Registry Query for Environmental Discovery
DET0209

Detection of Registry Query for Environmental Discovery

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0589 Analytic 0589
Windows

Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106
[TargetRegistryPath] Focus detection on registry hives or keys likely to reveal environment info (e.g., HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion).
[ParentProcess] May tune for suspicious parent processes such as cmd.exe, wscript.exe, or mshta.exe.
[TimeWindow] Controls how closely registry access must follow process creation for correlation.

Detected Techniques

1

Details

MITRE ID
DET0209
STIX ID
x-mitre-detection-strategy--106e32a9-29b7-4ec7-80cf-768662706490
Analytics
1
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.