Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1012

T1012Query Registry

T1012 — Query Registry is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 15 detection use cases covering it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
0Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

Windows Credential Access From Browser Password Store ESCU actions · hunting P Windows Credentials from Password Stores Chrome Extension Access ESCU actions · hunting P Windows Credentials from Password Stores Chrome LocalState Access ESCU actions · hunting P Windows Credentials from Password Stores Chrome Login Data Access ESCU actions · hunting P Windows Hosts File Access ESCU actions · hunting P Windows Non Discord App Access Discord LevelDB ESCU actions · hunting P Windows Post Exploitation Risk Behavior ESCU actions · alerting P Windows Product Key Registry Query ESCU actions · hunting P Windows Query Registry Browser List Application ESCU actions · hunting P Windows Query Registry UnInstall Program List ESCU actions · hunting P Windows Registry Entries Exported Via Reg ESCU actions · hunting P Windows Registry Entries Restored Via Reg ESCU actions · hunting P Windows Software Discovery Via PowerShell ESCU actions · hunting P Windows Modify Registry Reg Restore ESCU actions · hunting P Windows Query Registry Reg Save ESCU actions · hunting P