Files
Ares-mythic/documentation-payload/apollo/commands/reg_query.md
2026-04-14 12:17:24 +07:00

634 B

+++ title = "reg_query" chapter = false weight = 103 hidden = false +++

{{% notice info %}} Artifacts Generated: Registry Read {{% /notice %}}

Summary

Query subkeys of a specified registry key.

Arguments

subkeys

Hive

The registry key to retrieve subkeys for. This must be in the format of HKLM:\SYSTEM\Setup, where HKLM can be any of the following values:

  • HKLM
  • HKCU
  • HKU
  • HKCR
  • HKCC

Key (optional)

Registry key to query in the Hive for.

Usage

reg_query -Hive HKLM -Key System\\Setup

subkeys

MITRE ATT&CK Mapping

  • T1012