1200KM / simulation
T1112 Modify Registry — Attack Simulation
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to…
Technique description
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Disable Windows Toast Notifications
Procedure 003f466a-6010-4b15-803a-cbb478a314d7; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows OS Auto Update
Procedure 01b20ca8-c7a3-4d86-af59-059f15ed5474; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify UseTPMKeyPIN Registry entry
Procedure 02d8b9f7-1a51-4011-8901-2d55cca667f9; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disabling ShowUI Settings of Windows Error Reporting (WER)
Procedure 09147b61-40f6-4b2a-b6fb-9e73a3437c96; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- BlackByte Ransomware Registry Changes - Powershell
Procedure 0b79c06f-c788-44a2-8630-d69051f1123d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify UseTPMPIN Registry entry
Procedure 10b33fb0-c58b-44cd-8599-b6da5ad6384c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Win Defender Notification
Procedure 12e03af7-79f9-4f95-af48-d3f12f28a260; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activate Windows NoClose Group Policy Feature
Procedure 12f50e15-dbc6-478b-a801-a746e8ba1723; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify Registry of Current User Profile - cmd
Procedure 1324796b-d0f6-455a-b4ae-21ffee6aa6b9; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Javascript in registry
Procedure 15f44ea9-4571-4837-be9e-802431a7bfae; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Enable RDP via Registry (fDenyTSConnections)
Procedure 16bdbe52-371c-4ccf-b708-79fba61f1db4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows Add Registry Value to Load Service in Safe Mode without Network
Procedure 1dd59fb3-1cb3-4828-805d-cf80b4c3bbb5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activate Windows NoPropertiesMyDocuments Group Policy Feature
Procedure 20fc9daa-bd48-4325-9aff-81b967a84b1d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Requires the BitLocker PIN for Pre-boot authentication
Procedure 26fc7375-a551-4336-90d7-3f2817564304; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify Registry of Local Machine - cmd
Procedure 282f929a-6bc5-42b8-bd93-960c3ba35afe; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Abusing MyComputer Disk Fragmentation Path for Persistence
Procedure 3235aafe-b49d-451b-a1f1-d979fa65ddaf; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows Auto Update Option to Notify before download
Procedure 335a6b15-b8d2-4a3f-a973-ad69aa2620d7; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Terminal Server Client Connection History Cleared
Procedure 3448824b-3c35-4a9e-a8f5-f887f68bea21; elevation required; cleanup not declared. Not executed or individually validated.
- Mimic Ransomware - Allow Multiple RDP Sessions per User
Procedure 35727d9e-7a7f-4d0c-a259-dc3906d6e8b9; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Allow Simultaneous Download Registry
Procedure 37950714-e923-4f92-8c7c-51e4b6fffbf6; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Auto Reboot for current logon user
Procedure 396f997b-c5f8-4a96-bb2c-3c8795cf459d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Mimic Ransomware - Enable Multiple User Sessions
Procedure 39f1f378-ba8a-42b3-96dc-2a6540cfc1e3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify UsePIN Registry entry
Procedure 3ac0b30f-532f-43c6-8f01-fb657aaed7e4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tamper Win Defender Protection
Procedure 3b625eaa-c10d-4635-af96-3eae7d2a2f3c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Lock Workstation Feature
Procedure 3dacb0d2-46ee-4c27-ac1b-f9886bf91a56; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows HideSCANetwork Group Policy Feature
Procedure 3e757ce7-eca0-411a-9583-1c33b8508d52; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Abusing Windows TelemetryController Registry Key for Persistence
Procedure 4469192c-2d2d-4a3a-9758-1f31d937a92b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Security Center Notifications
Procedure 45914594-8df6-4ea9-b3cc-7eb9321a807e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Remote Desktop Security Settings Through Registry
Procedure 4b81bcfa-fb0a-45e9-90c2-e3efe5160140; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Enforce Smart Card Authentication Through Registry
Procedure 4c4bf587-fe7f-448f-ba8d-1ecec9db88be; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activate Windows NoTrayContextMenu Group Policy Feature
Procedure 4d72d4b1-fa7b-4374-b423-0fe326da49d2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- BlackByte Ransomware Registry Changes - CMD
Procedure 4f4e2f9f-6209-4fcf-9b15-3b7455706f5b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Adding custom paths for application execution
Procedure 573d15da-c34e-4c59-a7d2-18f20d92dfa3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Abusing MyComputer Disk Backup Path for Persistence
Procedure 599f3b5c-0323-44ed-bb63-4551623bf675; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activate Windows NoFileMenu Group Policy Feature
Procedure 5e27bdb4-7fd9-455d-a2b5-4b4b22c9dea4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Remote Desktop Protocol
Procedure 5f8e36de-37ca-455e-b054-a2584f043c06; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Event Viewer Registry Modification - Redirection URL
Procedure 6174be7f-5153-4afd-92c5-e0c3b7cdb5ae; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Remote Desktop Anti-Alias Setting Through Registry
Procedure 61d35188-f113-4334-8245-8c6556d43909; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- NetWire RAT Registry Key Creation
Procedure 65704cd4-6e36-4b90-b6c1-dc29a82c8e56; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Use Powershell to Modify registry to store logon credentials
Procedure 68254a85-aa42-4312-a695-38b7276307f8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Shutdown Button
Procedure 6e0d1131-2d7e-4905-8ca5-d6172f05d03d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- DisallowRun Execution Of Certain Applications
Procedure 71db768a-5a9c-4047-b5e7-59e01f188e84; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows Modify Show Compress Color And Info Tip Registry
Procedure 795d3248-0394-4d4d-8e86-4e8df2a2693f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Prefetch Through Registry
Procedure 7979dd41-2045-48b2-a54e-b1bc2415c9da; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify UseTPM Registry entry
Procedure 7c8c7bd8-0a5c-4514-a6a3-0814c5a98cf0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- RDP Authentication Level Override
Procedure 7e7b62e9-5f83-477d-8935-48600f38a3c6; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Windows HideSCAVolume Group Policy Feature
Procedure 7f037590-b4c6-4f13-b3cc-e424c5ab8ade; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Hide Windows Clock Group Policy Feature
Procedure 8023db1e-ad06-4966-934b-b6a0ae52689e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Event Viewer Registry Modification - Redirection Program
Procedure 81483501-b8a5-4225-8b32-52128e2f69db; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Snake Malware Registry Blob
Procedure 8318ad20-0488-4a64-98f4-72525a012f6b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Allow RDP Remote Assistance Feature
Procedure 86677d0e-0b5e-4a2b-b302-454175f9aa9e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows HideSCAPower Group Policy Feature
Procedure 8d85a5d8-702f-436f-bc78-fcd9119496fc; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activate Windows NoDesktop Group Policy Feature
Procedure 93386d41-525c-4a1b-8235-134a628dee17; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows Powershell Logging Disabled
Procedure 95b25212-91a7-42ff-9613-124aca6845a8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activate Windows NoControlPanel Group Policy Feature
Procedure a450e469-ba54-4de1-9deb-9023a6111690; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows HideSCAHealth Group Policy Feature
Procedure a4637291-40b1-4a96-8c82-b28f1d73e54e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Registry Tool
Procedure ac34b0f7-0f85-4ac0-b93e-3ced2bc69bb8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Setting Shadow key in Registry for RDP Shadowing
Procedure ac494fe5-81a4-4897-af42-e774cf005ecb; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Task Manager application
Procedure af254e70-dd0e-4de6-9afe-a994d9ea8b62; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify Internet Zone Protocol Defaults in Current User Registry - PowerShell
Procedure b1a4d687-ba52-4057-81ab-757c3dc0d3b5; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Modify UsePartialEncryptionKey Registry entry
Procedure b5169fd5-85c8-4b2c-a9b6-64cc0b9febef; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Turla Mosquito - Store Backdoor Path in OneDriveUpdate Registry Key
Procedure b6a03947-452c-4137-afaa-112b3c924fd6; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Modify EnableBDEWithNoTPM Registry entry
Procedure bacb3e73-8161-43a9-8204-a69fe0e4b482; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify registry to store logon credentials
Procedure c0413fb5-33e2-40b7-9b6f-60b29f4a7a18; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Notification Center
Procedure c0d6d67f-1f63-42cc-95c0-5fd6b20082ad; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows Add Registry Value to Load Service in Safe Mode with Network
Procedure c173c948-65e5-499c-afbe-433722ed5bd4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activities To Disable Secondary Authentication Detected By Modified Registry Value.
Procedure c26fb85a-fa50-4fab-a64a-c51f5dc538d5; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Suppress Win Defender Notifications
Procedure c30dada3-7777-4590-b970-dc890b8cf113; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Ursnif Malware Registry Key Creation
Procedure c375558d-7c25-45e9-bd64-7b23a97c1db0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Modify RDP-Tcp Initial Program Registry Entry
Procedure c691cee2-8d17-4395-b22f-00644c7f1c2d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify UseTPMKey Registry entry
Procedure c8480c83-a932-446e-a919-06a1fd1e512a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify Internet Zone Protocol Defaults in Current User Registry - cmd
Procedure c88ef166-50fa-40d5-a80c-e2b87d4180f7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Scarab Ransomware Defense Evasion Activities
Procedure ca8ba39c-3c5a-459f-8e15-280aec65a910; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Add domain to Trusted sites Zone
Procedure cf447677-5a4e-4937-a82c-e47d254afd57; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Do Not Connect To Win Update
Procedure d1de3767-99c2-4c6c-8c5a-4ba4586474c8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows CMD application
Procedure d2561a6d-72bd-408c-b150-13efe1801c2a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activate Windows NoSetTaskbar Group Policy Feature
Procedure d29b7faf-7355-4036-9ed3-719bd17951ed; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Error Reporting Settings
Procedure d2c9e41e-cd86-473d-980d-b6403562e3e1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activate Windows NoRun Group Policy Feature
Procedure d49ff3cc-8168-4123-b5b3-f057d9abbd55; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Change Password Feature
Procedure d4a6da40-618f-454d-9a9e-26af552aaeb0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Set-Up Proxy Server
Procedure d88a3d3b-d016-4939-a745-03638aafd21b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows LogOff Button
Procedure e246578a-c24d-46a7-9237-0213ff86fb0c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Enabling Remote Desktop Protocol via Remote Registry
Procedure e3ad8e83-3089-49ff-817f-e52f8c948090; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify EnableNonTPM Registry entry
Procedure e672a340-a933-447c-954c-d68db38a09b1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable UAC remote restrictions via LocalAccountTokenFilterPolicy
Procedure e8c7c404-b669-4cf9-bafd-fdad89a5bbb1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Enable Proxy Settings
Procedure eb0ba433-63e5-4a8c-a9f0-27c4192e1336; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Flush Shimcache
Procedure ecbd533e-b45d-4239-aeff-b857c6f6d68b; elevation required; cleanup not declared. Not executed or individually validated.
- Abusing MyComputer Disk Cleanup Path for Persistence
Procedure f2915249-4485-42e2-96b7-9bf34328d497; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Change Powershell Execution Policy to Bypass
Procedure f3a6cceb-06c9-48e5-8df8-8867a6814245; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Enabling Restricted Admin Mode via Command_Prompt
Procedure fe7974e5-5813-477b-a7bd-311d4f535e83; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activate Windows NoFind Group Policy Feature
Procedure ffbb407e-7f1d-4c95-b22e-548169db1fbd; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Activities To Disable Microsoft [FIDO Aka Fast IDentity Online] Authentication Detected By Modified Registry Value.
Procedure ffeddced-bb9f-49c6-97f0-3d07a509bf94; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Dragonfly · G0035
- Patchwork · G0040
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- FIN8 · G0061
- APT19 · G0073
- Gorgon Group · G0078
- APT38 · G0082
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Indrik Spider · G0119
- Aquatic Panda · G0143
- Ember Bear · G1003
- Earth Lusca · G1006
- LuminousMoth · G1014
- Volt Typhoon · G1017
- Saint Bear · G1031
- BlackByte · G1043
- APT42 · G1044
- Medusa Group · G1051
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.