Skip to content

S0075 Reg

Reg is a Windows utility used to interact with the Windows Registry. It can be used at the command-line interface to query, add, modify, and remove information. 1

Utilities such as Reg are known to be used by persistent threats. 2

Item Value
ID S0075
Associated Names
Type TOOL
Version 1.1
Created 31 May 2017
Last Modified 13 October 2022
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1112 Modify Registry Reg may be used to interact with and modify the Windows Registry of a local or remote system at the command-line interface.1
enterprise T1012 Query Registry Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface.1
enterprise T1552 Unsecured Credentials -
enterprise T1552.002 Credentials in Registry Reg may be used to find credentials in the Windows Registry.3

Groups That Use This Software

ID Name References
G0049 OilRig 56
G0010 Turla 7
G0075 Rancor 8
G0093 GALLIUM 9
G0035 Dragonfly 10

References