title: Exports Registry Key To a File id: f0e53e89-8d22-46ea-9db5-9d4796ee2f8a related: - id: 82880171-b475-4201-b811-e9c826cd5eaa type: similar status: test description: Detects the export of the target Registry key to a file. references: - https://lolbas-project.github.io/lolbas/Binaries/Regedit/ - https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f author: Oddvar Moe, Sander Wiebing, oscd.community date: 2020-10-07 modified: 2024-03-13 tags: - attack.exfiltration - attack.discovery - attack.t1012 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\regedit.exe' - OriginalFileName: 'REGEDIT.EXE' selection_cli: CommandLine|contains|windash: ' -E ' filter_1: # filters to avoid intersection with critical keys rule CommandLine|contains: - 'hklm' - 'hkey_local_machine' filter_2: CommandLine|endswith: - '\system' - '\sam' - '\security' condition: all of selection_* and not all of filter_* falsepositives: - Legitimate export of keys level: low