Windows Registry Query for System Language Using reg.exe

Flags reg.exe registry queries to Control\Nls\Language, indicating system language discovery on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Marco Pedrinazzi (@pedrinazziM) (InTheCyber) (SigmaHQ), DRL 1.1
Published
2026-01-09
Updated
2026-07-30

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process executions of reg.exe where the command line queries the registry path Control\Nls\Language. System language discovery can help an attacker infer user locale to guide targeting, regional payload customization, or evasion decisions. The detection relies on Windows process creation telemetry, matching both the reg.exe binary and the specific query terms in the command line.

Related detections3 linkedT1614.001 — drag to rearrange
CHCP CodePage Locale Lookup
Suspicious External IP Discovery via api.ipify.org
Windows CHCP Console Code Page Lookup Triggered From cmd.exe
Windows Registry Query for System Language Using reg.exe
Pivot detection · T1614.001 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.