Adversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information that can be used by the system or other programs. Adversaries may query the Registry looking for credentials and passwords that have been stored for use by other programs or services. Sometimes these credentials are used for automatic logons. Example commands to find Registry keys related to password information: (Citation: Pentestlab Stored Credentials) * Local Machine Hive: reg query HKLM /f password /t REG_SZ /s * Current User Hive: reg query HKCU /f password /t REG_SZ /s

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Password Policies
is blocked by Privileged Account Management
is blocked by Audit
is blocked by Detect Credential Discovery via Windows Registry Enumeration
is blocked by Access Restriction For Change
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Continuous Monitoring
is blocked by Encrypting Data At Rest
is blocked by Public Key Infrastructure (PKI)
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Authenticator Management
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Remote Access
is blocked by Information In Shared Resources
is blocked by Secure Software Development Practices (SSDP)
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Vulnerability Scanning
Impressum Deutsch Englisch