Reg
MITRE ATT&CK: S0075 View on attack.mitre.org
Aliases: reg.exe, Reg
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:32:36
Context
Reg is a Windows utility used to interact with the Windows Registry. It can be used at the command-line interface to query, add, modify, and remove information. Utilities such as Reg are known to be used by persistent threats.
Detection coverage
- 91 Sigma rules
Malware & tools used
- Credentials in Registry (attack-pattern)
- Query Registry (attack-pattern)
- Modify Registry (attack-pattern)
Used by threat actors
- Operation Honeybee (campaign)
- Gamaredon Group (threat-actor)
- Volt Typhoon (threat-actor)
- Turla (threat-actor)
- Dragonfly (threat-actor)
- GALLIUM (threat-actor)
- OilRig (threat-actor)
- Rancor (threat-actor)
- Daggerfly (threat-actor)
Reports & references
- MITRE ATT&CK — S0075 (report)
- blogs.jpcert.or.jp — Windows Commands Abused By Attackers (report)
- Microsoft — Cc732643 (report)