﻿---
title: Query Registry using Built-in Tools
description: This rule identifies the execution of commands that can be used to query the Windows Registry. Adversaries may query the registry to gain situational...
url: https://www.elastic.co/elastic/docs-builder/docs/4302/reference/security/prebuilt-rules/rules_building_block/discovery_generic_registry_query
products:
  - Elastic Security
---

# Query Registry using Built-in Tools
This rule identifies the execution of commands that can be used to query the Windows Registry. Adversaries may query the
registry to gain situational awareness about the host, like installed security software, programs and settings.
**Rule type**: eql
**Rule indices**:
- logs-endpoint.events.process-*

**Rule Severity**: low
**Risk Score**: 21
**Runs every**: 
**Searches indices from**: `now-9m`
**Maximum alerts per execution**: 100
**References**:
**Tags**:
- Domain: Endpoint
- OS: Windows
- Use Case: Threat Detection
- Tactic: Discovery
- Rule Type: BBR
- Data Source: Elastic Defend
- Rule Type: Event Correlation (EQL)
- Platform: Windows

**Version**: 109
**Rule authors**:
- Elastic

**Rule license**: Elastic License v2

## Rule Query

```eql
process where host.os.type == "windows" and event.type == "start" and
  (
    (process.name : "reg.exe" and process.args : "query") or
    (
      process.name : ("powershell.exe", "powershell_ise.exe", "pwsh.exe") and
      process.args : ("get-childitem", "gci", "dir", "ls", "get-item", "gi", "get-itemproperty", "gp") and
      process.args : ("hkcu", "hkey_current_user", "hkey_local_machine", "hklm", "registry::*")
    )
  ) and
  not process.command_line : (
    "C:\\Windows\\system32\\reg.exe  query hklm\\software\\microsoft\\windows\\softwareinventorylogging /v collectionstate /reg:64",
    "reg  query \"HKLM\\Software\\WOW6432Node\\Npcap\" /ve  "
  )
```

**Framework:** MITRE ATT&CK
- Tactic:
  - Name: Discovery
- Id: TA0007
- Reference URL: [[https://attack.mitre.org/tactics/TA0007/](https://attack.mitre.org/tactics/TA0007/)](https://attack.mitre.org/tactics/TA0007/)
- Technique:
  - Name: Query Registry
- Id: T1012
- Reference URL: [[https://attack.mitre.org/techniques/T1012/](https://attack.mitre.org/techniques/T1012/)](https://attack.mitre.org/techniques/T1012/)