1200KM / simulation
T1012 Query Registry — Attack Simulation
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software. The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a…
Technique description
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software. The Registry contains a significant amount of information about the operating system, configuration, software, and security. Information can easily be queried using the Reg utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Query Registry with Powershell cmdlets
Procedure 0434d081-bb32-42ce-bcbb-3548e4f2628f; elevation required; cleanup not declared. Not executed or individually validated.
- Enumerate COM Objects in Registry with Powershell
Procedure 0d80d088-a84c-4353-af1a-fc8b439f1564; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Check Software Inventory Logging (SIL) status via Registry
Procedure 5c784969-1d43-4ac7-8c3d-ed6d025ed10d; elevation required; cleanup not declared. Not executed or individually validated.
- Reg query for AlwaysInstallElevated status
Procedure 6fb4c4c5-f949-4fd2-8af5-ddbc61595223; elevation required; cleanup not declared. Not executed or individually validated.
- Query Registry
Procedure 8f7578c4-9863-4d83-875c-a565573bbdf0; elevation required; cleanup not declared. Not executed or individually validated.
- Inspect SystemStartOptions Value in Registry
Procedure 96257079-cdc1-4aba-8705-3146e94b6dce; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Dragonfly · G0035
- Stealth Falcon · G0038
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- APT39 · G0087
- Kimsuky · G0094
- APT41 · G0096
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- ZIRCONIUM · G0128
- Volt Typhoon · G1017
- Daggerfly · G1034
- BlackByte · G1043
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.