BIOC
Informational
✕
Registry credentials extraction
Attackers may extract credentials from the Registry using system commands.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Credential Access
- Status:
- Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials in Registry (T1552.002)
Indicator:
Process action type = execution AND target process cmd = * query* password* AND target process name = reg.exe
Preventable: yes