Skip to content
Threat Feed

Tag

Windows-Registry

6 briefs RSS
high advisory

Modification of WDigest UseLogonCredential Registry Key

Adversaries modify the WDigest UseLogonCredential registry key to downgrade credential protection and enable the storage of clear-text passwords in memory for exfiltration via LSASS.

credential-theft persistence defense-impairment windows-registry
1r 2t
high advisory

Detection of Windows Service Binaries in Suspicious Directories

Adversaries often achieve persistence by registering malicious Windows services with binaries located in writeable or temp directories to evade detection.

persistence defense-impairment windows-registry detection-engineering
1r 1t
high advisory

Detection of .NET Framework ETW Evasion via Registry Modification

Attackers can disable .NET Framework Event Tracing for Windows (ETW) by modifying registry environment variables, effectively blinding EDR solutions and security telemetry to malicious managed-code execution.

.NET Framework defense-evasion windows-registry .net
1r 1t
medium advisory

Windows Defender Signature Retirement Disabled via Registry Modification

An attacker disables Windows Defender's signature retirement feature by modifying a registry key, potentially reducing its effectiveness in detecting threats by allowing older, less relevant signatures to persist.

Windows Defender +3 defense-evasion windows-registry windows-defender
2r 1t
high advisory

Windows Defender Network Protection Disabled via Registry Modification

This analytic detects modifications to the Windows registry to disable Windows Defender Network Protection, potentially leaving the system vulnerable to network-based threats.

Windows Defender defense-evasion privilege-escalation windows-registry
2r 1t
medium advisory

Windows Defender Quick Scan Interval Modification

Detection of modifications to the Windows registry that change the Windows Defender Quick Scan Interval, potentially impairing its ability to detect malware promptly.

Splunk Enterprise +3 defense-evasion windows-registry windows-defender endpoint
2r 1t