What MITRE ATT&CK T1112: Modify Registry (Defense Evasion) requires
MITRE ATT&CK T1112 covers adversary modification of the Windows Registry to hide configuration, persist, disable security tools, or evade detection. Common targets: Run keys, Services, Defender exclusions, EnableLUA UAC, IFEO (Image File Execution Options) debuggers. Compliance: NIST 800-53 SI-7, CM-2, CM-6, AU-2, ISO 27001 A.8.32, A.8.16, PCI DSS Req 10.4, CIS Controls v8 Control 4.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1112/
SHA-256 integrity: 36bc4164754e8b64a5951b2e47449ebc2545f2bb31ef303af13c134f882dd5c0
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1112: Modify Registry (https://attack.mitre.org/techniques/T1112/)
- NIST SP 800-53 Rev 5: SI-7, CM-2, CM-6, AU-2
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1112-modify-registry.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1112-modify-registry.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1112-modify-registry
- Back to registry: Browse all 10,085 compliance nodes