1200KM / detection
T1552.002 Credentials in Registry — Detection Rules
Detection workspace for T1552.002 Credentials in Registry: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- SAM Registry Hive Handle Request · test · high · {"product":"windows","service":"security"}
- Enumeration for Credentials in Registry · test · medium · {"category":"process_creation","product":"windows"}
- Enumeration for 3rd Party Creds From CLI · test · medium · {"category":"process_creation","product":"windows"}
- Registry Export of Third-Party Credentials · experimental · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0250 Detect Credential Discovery via Windows Registry Enumeration
AN0694 Analytic 0694
Defenders observe command-line executions or API-based registry reads targeting sensitive paths like HKLM or HKCU with keyword filters such as 'password', 'cred', or 'logon'. Typically performed by Reg.exe, PowerShell, custom binaries, or offensive tools such as Cobalt Strike. Correlation with process ancestry and command-line arguments indicates suspicious credential discovery activity.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.