Uncommon sensitive filesystem registry hive access
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
OS Credential Dumping (T1003), OS Credential Dumping: Security Account Manager (T1003.002)
Severity
Informational
Description
A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping.
Attacker's Goals
Adversary may attempt to extract credentials from the Windows Registry
Credentials can then be used to perform lateral movement and access restricted information.
Investigative actions
Investigate the process that tried to access the registry hive file.
Investigate the actions of the user, for which his credentials were stored in the registry hive file.
Variations
Was this helpful?
