BIOC
Low
✕
Installation of Cain & Abel password recovery tool
A process created a Registry key associated with the common password cracking tool Cain & Abel.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Credential Access
- Status:
- Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Indicator:
Registry action type = set_registry_value , create_registry_key AND registry key name = *\software\cain* Host host os = windows
Preventable: yes