Windows reg.exe Registry Save/Export of Third-Party Credential Paths

Alerts on reg.exe save/export commands targeting registry keys tied to third-party credential data.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-05-22
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process executions of reg.exe where the command line includes both registry save/export indicators and targets specific third-party application registry paths associated with credentials. Attackers can use reg.exe to extract sensitive configuration data directly from the registry for credential access. The detection relies on Windows process creation telemetry, matching the reg.exe binary and inspecting the command line for save/export terms and known registry subkey paths.

Related detections4 linkedT1552.002 — drag to rearrange
Suspicious Registry Query for Stored Credentials (via process_creation)
Windows CLI Enumeration of 3rd-Party Credential Registry Keys
Windows reg.exe Credential Enumeration via Registry Query (HKLM/HKCU)
Windows Security Event 4656: SAM Registry Hive Key Handle Requested
Windows reg.exe Registry Save/Export of Third-Party Credential Paths
Pivot detection · T1552.002 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.