Reg is the Windows built-in command-line utility used to query, enumerate, and dump Windows Registry data on local or remote systems. In the provided content it is associated with adversarial use of the Registry for discovery and credential access, including gathering details from the Windows Registry and finding credentials stored there. The content specifically states that Daggerfly used Reg to dump the SAM, SYSTEM, and SECURITY registry hives from victim machines. More broadly, the referenced activity aligns with querying Registry keys and values to collect host and configuration information and to obtain unsecured credentials stored in the Registry. High-confidence examples in the content include use of reg query against Registry paths such as HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default, HKEY_CURRENT_USER\Software<username>\PuTTY\Sessions, and HKLM\SOFTWARE for discovery of RDP, PuTTY, installed software, and related system information. The only directly named threat association for Reg in the content is Daggerfly.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Daggerfly has used Reg to dump various Windows registry hives from victim machines.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The content includes hive extraction activity such as "Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines" and "Indrik Spider has used a service account to extract copies of the Security Registry hive."
Adversaries may search the Registry on compromised systems for insecurely stored credentials... Example commands to find Registry keys related to password information: Local Machine Hive: reg query HKLM /f password /t REG_SZ /s Current User Hive: reg query HKCU /f password /t REG_SZ /s
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows command-line utility that can be used to query the Registry and locate stored credentials.
Command-line utility used to gather details from local or remote Windows Registry hives.
Windows command-line utility used to query and gather Registry information locally or remotely.
Windows command-line utility used to query/export registry data locally or remotely (often abused by attackers).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.