TACTIC: DEFENSE EVASION

Modify Registry (T1112): real cases

MITRE Definition ↗
Adversaries modify the Windows registry to hide artifacts and disable security controls.

Key Facts

Technique ID
T1112
Defense Evasion
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1112.
  • Tactical Phase: Defense Evasion.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Plea Agreement ¶ 6, Page 14
"Netwalker modified registry keys under HKLM\SYSTEM\CurrentControlSet\Control\Lsa to weaken local security authority validation."
U.S. District Court for the Middle District of Florida View full case dossier →