Analytics BIOC
Low
✕
Uncommon sensitive registry hive dump
A sensitive registry hive was extracted, which is used for accessing credentials.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Attacker's goals:
Adversary may attempt to extract credentials from the Windows Registry Credentials can then be used to perform lateral movement and access restricted information.
Investigative actions:
Investigate the process that tried to access the registry hive. Investigate the actions of the user for which his credentials were stored in the registry hive.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- Uncommon sensitive registry hive dump by unsigned and rare process High (parent: Low)
- Uncommon sensitive registry hive dump by injected process High (parent: Low)
- Uncommon sensitive registry hive dump by reg.exe lolbin process which was executed by rare causality process High (parent: Low)
- Uncommon sensitive registry hive dump by reg.exe lolbin process Medium (parent: Low)