Tag
high
advisory
Credential Acquisition via Registry Hive Dumping
2 rules 1 TTPDetects attempts to export sensitive Windows registry hives (SAM/SECURITY) using reg.exe, potentially leading to credential compromise.
Elastic Endgame +6
credential-access
registry-dump
windows
2r
1t
high
advisory
Credential Acquisition via Registry Hive Dumping
2 rules 2 TTPsAttackers may dump the SECURITY and/or SAM hives to obtain credentials stored in the host by using the Windows reg.exe tool.
Windows
credential-access
registry-dump
2r
2t