BIOC Low

Installation of Cain & Abel password recovery tool

A process created a Registry key associated with the common password cracking tool Cain & Abel.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Credential Access
Status:
Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Indicator:

Registry action type = set_registry_value , create_registry_key AND registry key name = *\software\cain* Host host os = windows

Preventable: yes