Registry Query for Installed Software via Reg.Exe

Rule Info

Name
Registry Query for Installed Software via Reg.Exe
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects usage of reg.exe to enumerate installed software via registry queries. Adversaries may use reg.exe to query registry keys that list installed software as part of their reconnaissance activities to identify potential targets or gather information about the software environment.
Date
2026-04-03 00:00:00
Modified
None
Id
d301c3b7-9ed0-4a8b-824e-3ca91d537bb3
Tags
attack.discovery attack.t1518
Type
Nextron Sigma feed only (private)

Rule History