Analytics BIOC
Informational
✕
Uncommon sensitive filesystem registry hive access
A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003) OS Credential Dumping: Security Account Manager (T1003.002)
Attacker's goals:
Adversary may attempt to extract credentials from the Windows Registry Credentials can then be used to perform lateral movement and access restricted information.
Investigative actions:
Investigate the process that tried to access the registry hive file. Investigate the actions of the user, for which his credentials were stored in the registry hive file.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- Uncommon filesystem registry SAM hive access by a lolbin actor in a shadow copy folder High (parent: Informational)
- Uncommon sensitive filesystem registry hive access by a lolbin actor in a shadow copy folder Medium (parent: Informational)
- Uncommon sensitive filesystem registry hive access by a rare unsigned actor in a shadow copy folder Medium (parent: Informational)
- Uncommon sensitive filesystem registry hive access by a rare unsigned actor Low (parent: Informational)