1200KM / detection
T1112 Modify Registry — Detection Rules
Detection workspace for T1112 Modify Registry: 78 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Remote Registry Lateral Movement · test · high · {"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:338cd001-2244-31f1-aaaa-900038001003\""}
- ETW Logging Disabled In .NET Processes - Registry · test · high · {"product":"windows","service":"security"}
- NetNTLM Downgrade Attack · test · high · {"product":"windows","service":"security","definition":"Requirements: Audit Policy : Object Access > Audit Registry (Success)"}
- Sysmon Channel Reference Deletion · test · high · {"product":"windows","service":"security"}
- Registry Modification Attempt Via VBScript - PowerShell · experimental · medium · {"category":"ps_script","product":"windows"}
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE · test · high · {"category":"process_creation","product":"windows"}
- Security Event Logging Disabled via MiniNt Registry Key - Process · experimental · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Desktop Background Change Using Reg.EXE · test · medium · {"product":"windows","category":"process_creation"}
- Potential Suspicious Registry File Imported Via Reg.EXE · test · medium · {"category":"process_creation","product":"windows"}
- RestrictedAdminMode Registry Value Tampering - ProcCreation · test · high · {"product":"windows","category":"process_creation"}
- Enable LM Hash Storage - ProcCreation · test · high · {"product":"windows","category":"process_creation"}
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE · test · high · {"product":"windows","category":"process_creation"}
- Reg Add Suspicious Paths · test · high · {"category":"process_creation","product":"windows"}
- Imports Registry Key From a File · test · medium · {"category":"process_creation","product":"windows"}
- Imports Registry Key From an ADS · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Registry Modification From ADS Via Regini.EXE · test · high · {"category":"process_creation","product":"windows"}
- Registry Modification Via Regini.EXE · test · low · {"category":"process_creation","product":"windows"}
- ShimCache Flush · stable · high · {"category":"process_creation","product":"windows"}
- Run Once Task Execution as Configured in Registry · test · low · {"product":"windows","category":"process_creation"}
- Non-privileged Usage of Reg or Powershell · test · high · {"category":"process_creation","product":"windows"}
- Registry Modification of MS-settings Protocol Handler · test · medium · {"category":"process_creation","product":"windows"}
- User Shell Folders Registry Modification via CommandLine · experimental · high · {"category":"process_creation","product":"windows"}
- Registry Modification Attempt Via VBScript · experimental · medium · {"category":"process_creation","product":"windows"}
- Suspicious VBoxDrvInst.exe Parameters · test · medium · {"category":"process_creation","product":"windows"}
- Registry Manipulation via WMI Stdregprov · experimental · medium · {"category":"process_creation","product":"windows"}
- Terminal Server Client Connection History Cleared - Registry · test · high · {"category":"registry_delete","product":"windows"}
- Removal of Potential COM Hijacking Registry Keys · test · medium · {"product":"windows","category":"registry_delete"}
- Disable Security Events Logging Adding Reg Key MiniNt · test · high · {"category":"registry_event","product":"windows"}
- Wdigest CredGuard Registry Modification · test · high · {"category":"registry_event","product":"windows"}
- Registry Entries For Azorult Malware · test · critical · {"product":"windows","category":"registry_event"}
- Potential Qakbot Registry Activity · test · high · {"category":"registry_event","product":"windows"}
- NetNTLM Downgrade Attack - Registry · test · high · {"product":"windows","category":"registry_event"}
- RedMimicry Winnti Playbook Registry Manipulation · test · high · {"product":"windows","category":"registry_event"}
- Run Once Task Configuration in Registry · test · medium · {"product":"windows","category":"registry_event"}
- Registry Tampering by Potentially Suspicious Processes · experimental · medium · {"category":"registry_event","product":"windows"}
- Allow RDP Remote Assistance Feature · test · medium · {"category":"registry_set","product":"windows"}
- New BgInfo.EXE Custom DB Path Registry Configuration · test · medium · {"category":"registry_set","product":"windows"}
- New BgInfo.EXE Custom VBScript Registry Configuration · test · medium · {"category":"registry_set","product":"windows"}
- New BgInfo.EXE Custom WMI Query Registry Configuration · test · medium · {"category":"registry_set","product":"windows"}
- ClickOnce Trust Prompt Tampering · test · medium · {"category":"registry_set","product":"windows"}
- CrashControl CrashDump Disabled · test · medium · {"product":"windows","category":"registry_set"}
- Security Event Logging Disabled via MiniNt Registry Key - Registry Set · experimental · high · {"category":"registry_set","product":"windows"}
- Service Binary in Suspicious Folder · test · high · {"category":"registry_set","product":"windows"}
- Potentially Suspicious Desktop Background Change Via Registry · test · medium · {"product":"windows","category":"registry_set"}
- DHCP Callout DLL Installation · test · high · {"category":"registry_set","product":"windows"}
- Disable Internal Tools or Feature in Registry · test · medium · {"category":"registry_set","product":"windows"}
- Disable Windows Security Center Notifications · test · medium · {"category":"registry_set","product":"windows"}
- Windows Event Log Access Tampering Via Registry · experimental · high · {"category":"registry_set","product":"windows"}
- Add DisallowRun Execution to Registry · test · medium · {"category":"registry_set","product":"windows"}
- DNS-over-HTTPS Enabled by Registry · test · medium · {"product":"windows","category":"registry_set"}
- New DNS ServerLevelPluginDll Installed · test · high · {"product":"windows","category":"registry_set"}
- ETW Logging Disabled In .NET Processes - Sysmon Registry · test · high · {"product":"windows","category":"registry_set"}
- Change User Account Associated with the FAX Service · test · high · {"product":"windows","category":"registry_set"}
- Change the Fax Dll · test · high · {"product":"windows","category":"registry_set"}
- Registry Hide Function from User · test · medium · {"category":"registry_set","product":"windows"}
- RestrictedAdminMode Registry Value Tampering · test · high · {"product":"windows","category":"registry_set"}
- NET NGenAssemblyUsageLog Registry Key Tamper · test · high · {"product":"windows","category":"registry_set"}
- Trust Access Disable For VBApplications · test · high · {"category":"registry_set","product":"windows"}
- Outlook EnableUnsafeClientMailRules Setting Enabled - Registry · test · high · {"category":"registry_set","product":"windows"}
- Macro Enabled In A Potentially Suspicious Document · test · high · {"category":"registry_set","product":"windows"}
- Uncommon Microsoft Office Trusted Location Added · test · high · {"category":"registry_set","product":"windows"}
- Office Macros Warning Disabled · test · high · {"category":"registry_set","product":"windows"}
- Potential Persistence Via Custom Protocol Handler · test · medium · {"category":"registry_set","product":"windows"}
- Potential Persistence Via Event Viewer Events.asp · test · medium · {"category":"registry_set","product":"windows"}
- Modification of IE Registry Settings · test · low · {"category":"registry_set","product":"windows"}
- Potential Persistence Via Outlook Home Page · test · high · {"product":"windows","category":"registry_set"}
- Potential Persistence Via Outlook Today Page · test · high · {"product":"windows","category":"registry_set"}
- Registry Modification for OCI DLL Redirection · experimental · high · {"category":"registry_set","product":"windows"}
- PowerShell Logging Disabled Via Registry Key Tampering · test · high · {"category":"registry_set","product":"windows"}
- ETW Logging Disabled For rpcrt4.dll · test · low · {"product":"windows","category":"registry_set"}
- ETW Logging Disabled For SCM · test · low · {"product":"windows","category":"registry_set"}
- Registry Explorer Policy Modification · test · medium · {"category":"registry_set","product":"windows"}
- Activate Suppression of Windows Security Center Notifications · test · medium · {"category":"registry_set","product":"windows"}
- Enable LM Hash Storage · test · high · {"product":"windows","category":"registry_set"}
- RDP Sensitive Settings Changed to Zero · test · medium · {"category":"registry_set","product":"windows"}
- RDP Sensitive Settings Changed · test · high · {"category":"registry_set","product":"windows"}
- Wdigest Enable UseLogonCredential · test · high · {"category":"registry_set","product":"windows"}
- Winlogon AllowMultipleTSSessions Enable · test · medium · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0280 Behavior-Based Registry Modification Detection on Windows
AN0781 Analytic 0781
Behavior chain involving abnormal registry modifications via CLI, PowerShell, WMI, or direct API calls, especially targeting persistence, privilege escalation, or defense evasion keys, potentially followed by service restart or process execution. Such as editing Notify/Userinit/Startup keys, or disabling SafeDllSearchMode.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Dragonfly · G0035
- Patchwork · G0040
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- FIN8 · G0061
- APT19 · G0073
- Gorgon Group · G0078
- APT38 · G0082
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Indrik Spider · G0119
- Aquatic Panda · G0143
- Ember Bear · G1003
- Earth Lusca · G1006
- LuminousMoth · G1014
- Volt Typhoon · G1017
- Saint Bear · G1031
- BlackByte · G1043
- APT42 · G1044
- Medusa Group · G1051
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.