Tag
medium
advisory
COM Hijacking via TreatAs Registry Modification
1 rule 1 TTPAdversaries leverage the COM TreatAs registry key to achieve persistence or privilege escalation by redirecting CLSID lookups to malicious COM objects.
persistence
privilege-escalation
registry-tampering
1r
1t
high
advisory
Detection of Microsoft Office Protected View Disablement
2 rules 1 TTPAdversaries modify registry keys to disable Microsoft Office Protected View security controls, facilitating the execution of malicious documents.
Microsoft Office
defense-impairment
registry-tampering
microsoft-office
persistence
privilege-escalation
registry
windows
office
2r
1t
updated
medium
threat
Registry Modification to Disable Privacy Settings Experience
1 ruleAdversaries, including those observed deploying LockBit Black, modify registry keys to disable the Windows Privacy Settings Experience as part of a defense impairment strategy.
LockBit Black
defense-impairment
registry-tampering
1r
high
threat
ShrinkLocker Ransomware BitLocker Registry Tampering
1 rule 1 TTPThe ShrinkLocker ransomware actor exploits native Windows registry configurations to manipulate BitLocker encryption behavior, bypassing security requirements to facilitate unauthorized data encryption.
Windows
ShrinkLocker
ransomware
defense-evasion
registry-tampering
1r
1t