Analytics BIOC Low

Uncommon sensitive registry hive dump

A sensitive registry hive was extracted, which is used for accessing credentials.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Attacker's goals:

Adversary may attempt to extract credentials from the Windows Registry Credentials can then be used to perform lateral movement and access restricted information.

Investigative actions:

Investigate the process that tried to access the registry hive. Investigate the actions of the user for which his credentials were stored in the registry hive.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • Uncommon sensitive registry hive dump by unsigned and rare process High (parent: Low)
  • Uncommon sensitive registry hive dump by injected process High (parent: Low)
  • Uncommon sensitive registry hive dump by reg.exe lolbin process which was executed by rare causality process High (parent: Low)
  • Uncommon sensitive registry hive dump by reg.exe lolbin process Medium (parent: Low)