Windows Regedit Exports Registry Hives to Files

Flags regedit.exe command lines exporting SYSTEM/SAM/SECURITY hives from HKLM to files.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Oddvar Moe, Sander Wiebing, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-12
Updated
2026-07-30

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process executions of regedit.exe where the command line includes the hive export switch and targets HKLM-related hives such as SYSTEM, SAM, and SECURITY. Exporting critical registry hives to files can enable discovery and facilitate offline analysis or credential-related follow-on activity. It relies on Windows process creation telemetry, including the executable name/path and the full command line arguments.

Related detections9 linkedT1012 — drag to rearrange
Registry Query for WDigest
Suspicious Installed Software Enumeration via Registry Uninstall Key Query
Windows WMI StdRegProv Registry Enumeration via wmic.exe
PowerShell Registry Reconnaissance Indicators on Windows via Script Block Logging
Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Windows Security: Suspicious Registry Access to ADHealthAgent Health Service Agent Keys
Windows Security: Access to Azure AD Health Monitoring Agent Registry Key
Windows Registry Key Export via regedit.exe (-E) to File
Windows Security: checkadmin.exe TargetUserName starting with Administr (Event ID 4799)
Windows Regedit Exports Registry Hives to Files
Pivot detection · T1012 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.