Standardseverity: MediumStable

CAPEC-203Manipulate Registry Information

Abstraction
Standard
Status
Stable
Severity
Medium

Description

An adversary exploits a weakness in authorization in order to modify content within a registry (e.g., Windows Registry, Mac plist, application registry). Editing registry information can permit the adversary to hide configuration information or remove indicators of compromise to cover up activity. Many applications utilize registries to store configuration and service information. As such, modification of registry information can affect individual services (affecting billing, authorization, or even allowing for identity spoofing) or the overall configuration of a targeted application. For example, both Java RMI and SOAP use registries to track available services. Changing registry values is sometimes a preliminary step towards completing another attack pattern, but given the long term usage of many registry values, manipulation of registry information could be its own end.

Related weaknesses· 1

CWE-15

MITRE ATT&CK crosswalk· 2

T1112: Modify RegistryT1647: Plist Modification

Related attack patterns· 1

CAPEC-176 (ChildOf)

Exploits1

TypeTargetConfidenceTier
WeaknessExternal Control of System or Configuration Settingcwe-15100%live

Related to2

TypeTargetConfidenceTier
TechniquePlist File Modificationt1647100%live
TechniqueModify Registryt1112100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Collect Data from Registries
CAPEC
DEPRECATED: Registry Manipulation
CAPEC
Configuration/Environment Manipulation
CAPEC
Poison Web Service Registry
CAPEC
Modification of Registry Run Keys
CAPEC
File Manipulation
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.