// MITRE ATT&CK
T1112 · Modify Registry
🎯 Defense Impairment Windows
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows comma...
How to detect & mitigate it
Detecting Modify Registry starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1687
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.