Hide Navigation Hide TOC System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) Restricting system configuration modifications to a specific user or group of users. Cluster A Galaxy A Cluster B Galaxy B Level Credentials in Registry - T1552.002 (341e222a-a6e3-4f6f-b69c-831d792b1580) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 System Language Discovery - T1614.001 (c1b68a96-3c48-49ea-a6c0-9b27359f9c19) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Component Object Model Hijacking - T1546.015 (bc0f5e80-91c0-4e04-9fbb-e4e332c85dae) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Windows Service - T1543.003 (2959d63f-73fd-46a1-abd2-109d7dcede32) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Add-ins - T1137.006 (34f1d81d-fe88-4f97-bd3b-a3164536255d) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Modify Registry - T1112 (57340c81-c025-4189-8fa0-fc7ede51bae4) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 MMC - T1218.014 (ffbcfdb0-de22-4106-9ed3-fc23c8a01407) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Elevated Execution with Prompt - T1548.004 (b84903f0-c7d5-435d-a69e-de47cc3578c0) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Image File Execution Options Injection - T1546.012 (6d4a7fb3-5a24-42be-ae61-6728a2b581f6) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Query Registry - T1012 (c32f7008-9fea-41f7-8366-5eb9b74bd896) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Hidden File System - T1564.005 (dfebc3b7-d19d-450b-81c7-6dafe4184c04) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Hidden Window - T1564.003 (cbb66055-0325-4111-aca0-40547b6ad5b0) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Rogue Domain Controller - T1207 (564998d8-ab3e-4123-93fb-eccaa6b9714a) Attack Pattern System Configuration Permissions (ac54cd72-5a21-5025-95fb-39b096f0ee0f) MITRE D3FEND 1 Credentials in Registry - T1552.002 (341e222a-a6e3-4f6f-b69c-831d792b1580) Attack Pattern Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) Attack Pattern 2 System Language Discovery - T1614.001 (c1b68a96-3c48-49ea-a6c0-9b27359f9c19) Attack Pattern System Location Discovery - T1614 (c877e33f-1df6-40d6-b1e7-ce70f16f4979) Attack Pattern 2 Event Triggered Execution - T1546 (b6301b64-ef57-4cce-bb0b-77026f14a8db) Attack Pattern Component Object Model Hijacking - T1546.015 (bc0f5e80-91c0-4e04-9fbb-e4e332c85dae) Attack Pattern 2 Windows Service - T1543.003 (2959d63f-73fd-46a1-abd2-109d7dcede32) Attack Pattern Create or Modify System Process - T1543 (106c0cf6-bf73-4601-9aa8-0945c2715ec5) Attack Pattern 2 Add-ins - T1137.006 (34f1d81d-fe88-4f97-bd3b-a3164536255d) Attack Pattern Office Application Startup - T1137 (2c4d4e92-0ccf-4a97-b54c-86d662988a53) Attack Pattern 2 System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) Attack Pattern MMC - T1218.014 (ffbcfdb0-de22-4106-9ed3-fc23c8a01407) Attack Pattern 2 Elevated Execution with Prompt - T1548.004 (b84903f0-c7d5-435d-a69e-de47cc3578c0) Attack Pattern Abuse Elevation Control Mechanism - T1548 (67720091-eee3-4d2d-ae16-8264567f6f5b) Attack Pattern 2 Image File Execution Options Injection - T1546.012 (6d4a7fb3-5a24-42be-ae61-6728a2b581f6) Attack Pattern Event Triggered Execution - T1546 (b6301b64-ef57-4cce-bb0b-77026f14a8db) Attack Pattern 2 Hidden File System - T1564.005 (dfebc3b7-d19d-450b-81c7-6dafe4184c04) Attack Pattern Hide Artifacts - T1564 (22905430-4901-4c2a-84f6-98243cb173f8) Attack Pattern 2 Hide Artifacts - T1564 (22905430-4901-4c2a-84f6-98243cb173f8) Attack Pattern Hidden Window - T1564.003 (cbb66055-0325-4111-aca0-40547b6ad5b0) Attack Pattern 2