Skip to content

Latest commit

 

History

History
14 lines (9 loc) · 512 Bytes

Query_registry.md

File metadata and controls

14 lines (9 loc) · 512 Bytes

Query Registry

MITRE ATT&CK technique T1012

Tactic: Discovery

Platform: Windows

Deception Techniques

  • Create fake registry objects and monitor access to them using Windows Registry Auditing.
  • Create registry objects containing breadcrumbs or honeytokens.

Useful Resources

  • Audit Registry - Audit Registry allows you to audit attempts to access registry objects