For the complete documentation index, see llms.txt. This page is also available as Markdown.

Uncommon sensitive filesystem registry hive access

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003), OS Credential Dumping: Security Account Manager (T1003.002)

Severity

Informational

Description

A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping.

Attacker's Goals

  • Adversary may attempt to extract credentials from the Windows Registry

  • Credentials can then be used to perform lateral movement and access restricted information.

Investigative actions

  • Investigate the process that tried to access the registry hive file.

  • Investigate the actions of the user, for which his credentials were stored in the registry hive file.

Variations

Uncommon filesystem registry SAM hive access by a lolbin actor in a shadow copy folder

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003), OS Credential Dumping: Security Account Manager (T1003.002)

Severity

High

Description

A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping.

Attacker's Goals

  • Adversary may attempt to extract credentials from the Windows Registry

  • Credentials can then be used to perform lateral movement and access restricted information.

Investigative actions

  • Investigate the process that tried to access the registry hive file.

  • Investigate the actions of the user, for which his credentials were stored in the registry hive file.

Uncommon sensitive filesystem registry hive access by a lolbin actor in a shadow copy folder

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003), OS Credential Dumping: Security Account Manager (T1003.002)

Severity

Medium

Description

A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping.

Attacker's Goals

  • Adversary may attempt to extract credentials from the Windows Registry

  • Credentials can then be used to perform lateral movement and access restricted information.

Investigative actions

  • Investigate the process that tried to access the registry hive file.

  • Investigate the actions of the user, for which his credentials were stored in the registry hive file.

Uncommon sensitive filesystem registry hive access by a rare unsigned actor in a shadow copy folder

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003), OS Credential Dumping: Security Account Manager (T1003.002)

Severity

Medium

Description

A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping.

Attacker's Goals

  • Adversary may attempt to extract credentials from the Windows Registry

  • Credentials can then be used to perform lateral movement and access restricted information.

Investigative actions

  • Investigate the process that tried to access the registry hive file.

  • Investigate the actions of the user, for which his credentials were stored in the registry hive file.

Uncommon sensitive filesystem registry hive access by a rare unsigned actor

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

OS Credential Dumping (T1003), OS Credential Dumping: Security Account Manager (T1003.002)

Severity

Low

Description

A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping.

Attacker's Goals

  • Adversary may attempt to extract credentials from the Windows Registry

  • Credentials can then be used to perform lateral movement and access restricted information.

Investigative actions

  • Investigate the process that tried to access the registry hive file.

  • Investigate the actions of the user, for which his credentials were stored in the registry hive file.

Was this helpful?