Insider Threat Matrix™

  • ID: AF007
  • Created: 25th May 2024
  • Updated: 05th July 2024
  • Platform: Windows
  • Contributor: The ITM Team

Modify Windows Registry

A subject may modify keys or key values within the Windows Registry to conceal actions they have conducted related to an infringement.


ID Name Description
AF007.001Delete or Modify Registry Key

The subject deletes or modifies Windows Registry keys to hinder an investigation by removing information that can be used by investigators. Many actions and configurations on a Windows system are logged or stored in the registry. Deleting these keys can make it harder for investigators to trace the attacker's steps and understand what changes were made to the system.

AF007.002Delete or Modify Registry Key Value

The subject deletes or modifies Windows Registry key values to hinder an investigation by removing information that can be used by investigators. Many actions and configurations on a Windows system are logged or stored in the registry. Deleting key values can make it harder for investigators to trace the attacker's steps and understand what changes were made to the system.