System Information Discovery via Registry Queries

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects attempts to gather system information directly from Windows Registry paths.

Severity

Attention

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@lazarg