ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF007.002
  • Created: 25th May 2024
  • Updated: 27th July 2024
  • Platform: Windows
  • Contributor: The ITM Team

Delete or Modify Registry Key Value

The subject deletes or modifies Windows Registry key values to hinder an investigation by removing information that can be used by investigators. Many actions and configurations on a Windows system are logged or stored in the registry. Deleting key values can make it harder for investigators to trace the attacker's steps and understand what changes were made to the system.