1200KM / detection
T1012 Query Registry — Detection Rules
Detection workspace for T1012 Query Registry: 9 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Azure AD Health Monitoring Agent Registry Keys Access · test · medium · {"product":"windows","service":"security"}
- Azure AD Health Service Agents Registry Keys Access · test · medium · {"product":"windows","service":"security"}
- SAM Registry Hive Handle Request · test · high · {"product":"windows","service":"security"}
- SysKey Registry Keys Access · test · high · {"product":"windows","service":"security"}
- HackTool - PCHunter Execution · test · high · {"category":"process_creation","product":"windows"}
- Potential Configuration And Service Reconnaissance Via Reg.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Exports Critical Registry Keys To a File · test · high · {"category":"process_creation","product":"windows"}
- Exports Registry Key To a File · test · low · {"category":"process_creation","product":"windows"}
- Registry Enumeration via WMI Stdregprov · experimental · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0209 Detection of Registry Query for Environmental Discovery
AN0589 Analytic 0589
Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Dragonfly · G0035
- Stealth Falcon · G0038
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- APT39 · G0087
- Kimsuky · G0094
- APT41 · G0096
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- ZIRCONIUM · G0128
- Volt Typhoon · G1017
- Daggerfly · G1034
- BlackByte · G1043
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.