Skip to content

S0075 Reg

Reg is a Windows utility used to interact with the Windows Registry. It can be used at the command-line interface to query, add, modify, and remove information. 1

Utilities such as Reg are known to be used by persistent threats. 2

Item Value
ID S0075
Associated Names
Type TOOL
Version 1.0
Created 31 May 2017
Last Modified 23 August 2021
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1112 Modify Registry Reg may be used to interact with and modify the Windows Registry of a local or remote system at the command-line interface.1
enterprise T1012 Query Registry Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface.1
enterprise T1552 Unsecured Credentials -
enterprise T1552.002 Credentials in Registry Reg may be used to find credentials in the Windows Registry.3

Groups That Use This Software

ID Name References
G0093 GALLIUM 4
G0075 Rancor 5
G0049 OilRig 67
G0010 Turla 8
G0072 Honeybee 9
G0035 Dragonfly 10

References

Back to top