Uncommon sensitive registry hive dump
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
OS Credential Dumping (T1003)
Severity
Low
Description
A sensitive registry hive was extracted, which is used for accessing credentials.
Attacker's Goals
Adversary may attempt to extract credentials from the Windows Registry
Credentials can then be used to perform lateral movement and access restricted information.
Investigative actions
Investigate the process that tried to access the registry hive.
Investigate the actions of the user for which his credentials were stored in the registry hive.
Variations
Was this helpful?
