Analytics BIOC Informational

Uncommon sensitive filesystem registry hive access

A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003) OS Credential Dumping: Security Account Manager (T1003.002)
Attacker's goals:

Adversary may attempt to extract credentials from the Windows Registry Credentials can then be used to perform lateral movement and access restricted information.

Investigative actions:

Investigate the process that tried to access the registry hive file. Investigate the actions of the user, for which his credentials were stored in the registry hive file.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • Uncommon filesystem registry SAM hive access by a lolbin actor in a shadow copy folder High (parent: Informational)
  • Uncommon sensitive filesystem registry hive access by a lolbin actor in a shadow copy folder Medium (parent: Informational)
  • Uncommon sensitive filesystem registry hive access by a rare unsigned actor in a shadow copy folder Medium (parent: Informational)
  • Uncommon sensitive filesystem registry hive access by a rare unsigned actor Low (parent: Informational)