BIOC Informational

Registry credentials extraction

Attackers may extract credentials from the Registry using system commands.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Credential Access
Status:
Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials in Registry (T1552.002)
Indicator:

Process action type = execution AND target process cmd = * query* password* AND target process name = reg.exe

Preventable: yes