MITRE ATT&CK Technique
T1012Query Registry
- First Reported
- Dec 17, 2025
- Latest Reported
- Sep 10, 2026
Official Description
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
The Registry contains a significant amount of information about the operating system, configuration, software, and security.(Citation: Wikipedia Windows Registry) Information can easily be queried using the [Reg](https://attack.mitre.org/software/S0075) utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from [Query Registry](https://attack.mitre.org/techniques/T1012) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
The Registry contains a significant amount of information about the operating system, configuration, software, and security.(Citation: Wikipedia Windows Registry) Information can easily be queried using the [Reg](https://attack.mitre.org/software/S0075) utility, though other means to access the Registry exist. Some of the information may help adversaries to further their operation within a network. Adversaries may use the information from [Query Registry](https://attack.mitre.org/techniques/T1012) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
- Tactics
- Discovery
- Platforms
- Windows
- MITRE Version
- 1.3
- Last Modified
- May 12, 2026
Reported Context (2)
- The built-in Get-ItemProperty handler reads and enumerates registry values. Zscaler Details SloppyRAT, a New Malware Linked to Ransomware Attacks
- Registry queries were used to identify virtualization hostnames and infrastructure. Lynx Ransomware Attack Began with Compromised RDP Credentials
Malware (4)
People (3)
MITRE ATT&CK (44)
Vendors (4)
Products (9)
Tools (2)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.