Skip to main content

Settings

IDDescriptionSignificance / Prevalence
BH12117Accesses registry settings.
BH12123Accesses/installs certificates.
BH12124Adds a new entry to the registry on a remote computer.
BH12126Adds a new subkey to the registry on a remote computer.
BH12127Adds a new entry to the registry.
BH12128Adds a new subkey to the registry.
BH12129Adds new users to a user group.
BH12131Adds credentials to the Windows Credential Manager.
BH12132Adds new certificates to trust store.
BH12133Adds new users to an active directory user group.
BH12135Adds or removes computer from a domain or workgroup.
BH12144Bypasses the default script execution policy.
BH12151Changes computer name.
BH12152Changes event log settings using WMI.
BH12155Changes operating system recovery settings using WMI.
BH12158Changes properties of a scheduled task.
BH12164Changes system domain information using WMI.
BH12165Changes system environment variables using WMI.
BH12166Changes system information using WMI.
BH12171Changes username or password.
BH12172Changes user account information using WMI.
BH12173Changes WMI service settings.
BH12181Clears content of items, such as registry keys.
BH12182Clears content of items, such as registry values.
BH12198Creates a new active directory user group.
BH12200Creates a new user account.
BH12201Creates a new local user group.
BH12210Creates event triggers on local or remote machines.
BH12211Creates new user accounts.
BH12212Creates or changes item properties, such as registry keys.
BH12218Creates new registry keys.
BH12224Deletes a local user group.
BH12229Deletes a subkey from the registry on a remote computer.
BH12230Deletes a user account.
BH12231Deletes an active directory user group.
BH12234Deletes credentials from the Windows Credential Manager.
BH12235Deletes entries from the registry on a remote computer.
BH12236Deletes entries from the registry.
BH12241Deletes the per-user audit policy for all users.
BH12242Deletes users using cmdkey.
BH12246Disables advanced boot options.
BH12247Disables Automatic Startup Repair.
BH12248Disables boot options editing.
BH12250Disables Emergency Management Services (EMS).
BH12251Disables failed boot warning messages at startup.
BH12254Disables recovery console.
BH12257Disables Startup Repair (Automatic Repair) at startup.
BH12258Disables the Adobe update service.
BH12259Disables the alerter service used to send administrative alerts to users.
BH12260Disables the Application Identity service.
BH12261Disables the Application Information service.
BH12262Disables the Application Management service.
BH12263Disables the BitLocker Drive Encryption service.
BH12264Disables the Credential Manager service.
BH12265Disables the Cryptographic services.
BH12266Disables the Desktop Window Manager Session Manager service.
BH12267Disables the Device Management Wireless Application Protocol service.
BH12269Disables the DNS Client service.
BH12270Disables the Dropbox update service.
BH12271Disables the Enterprise App Management service.
BH12272Disables the Extensible Authentication Protocol service.
BH12273Disables the File History service.
BH12274Disables the Google update service.
BH12275Disables the Microsoft Passport service.
BH12276Disables the Microsoft Smartcard Certificate Propagation service.
BH12277Disables the Microsoft Software Shadow Copy Provider service.
BH12278Disables the Microsoft Store Install service.
BH12279Disables the Microsoft Windows Shared Access service.
BH12282Disables the Network List service.
BH12283Disables the Network Location Awareness service.
BH12284Disables the Remote Access Connection Manager service.
BH12285Disables the Remote Desktop services.
BH12286Disables the Remote Procedure Call (RPC) service.
BH12287Disables the Secondary Logon service.
BH12288Disables the Server service.
BH12289Disables the SPP Notification service (used for software licensing activation and notification).
BH12290Disables the System Guard Runtime Monitor Broker service.
BH12291Disables the Task Scheduler service.
BH12292Disables the UPnP Device Host service.
BH12294Disables the Windows Backup service.
BH12295Disables the Windows Error Reporting service.
BH12298Disables the Windows License Manager service.
BH12299Disables the Windows Management Instrumentation service.
BH12300Disables the Windows Modules Installer service.
BH12301Disables the Windows Time service.
BH12363Immediately runs a scheduled task on a remote computer.
BH12364Immediately runs a scheduled task.
BH12365Imports a certificate.
BH12380Indicates whether or not a backup policy can perform bare metal recoveries from backups.
BH12398List all sessions connected to this machine.
BH12399List sessions from a given machine.
BH12413Manipulates proxy settings.
BH12414Manipulates settings that control features of third-party network services.
BH12415Manipulates settings that determine what information browser makes available to websites.
BH12416Manipulates settings that influence handling of network connections.
BH12421Modifies Boot.ini file settings.
BH12457Moves properties of items, such as registry values.
BH12466Prepares a hard drive with the partitions necessary for BitLocker Drive Encryption.
BH12477Registers itself as handler for a MIME type.
BH12478Registers itself as handler for a protocol.
BH12479Removes a computer from the domain.
BH12487Removes certificates.
BH12488Removes event triggers on local or remote machines.
BH12491Removes the per-user audit policy for a specified account or all accounts.
BH12492Removes the per-user audit policy for a specified account.
BH12493Removes the per-user audit policy for all accounts.
BH12494Removes user accounts.
BH12495Removes users from a user group.
BH12496Removes users from an active directory user group.
BH12532Returns all child certificates from a parent certificate used in a user request for the AD RMS cluster.
BH12533Returns all of the certificate enrollment policy server URL configurations.
BH12535Returns an App-V connection group object.
BH12538Returns the configuration for the DirectAccess client user experience.
BH12540Returns use-license information from an issuance license used in a user request for the Active Directory Rights Management Services (AD RMS) cluster.
BH12592Tampers with Active Directory Federation Services (AD FS) settings.
BH12593Tampers with Active Directory Rights Management Services (AD RMS) settings.
BH12594Tampers with Active Directory settings.
BH12596Tampers with App-V Client settings.
BH12597Tampers with AppLocker settings.
BH12598Tampers with audit policies.
BH12600Tampers with auto-disconnect time of the server service.
BH12603Tampers with Best Practices Analyzer settings.
BH12604Tampers with BitLocker settings.
BH12605Tampers with boot configuration.
BH12606Tampers with boot debugger of Windows Boot Manager.
BH12607Tampers with Boot Event Collector settings.
BH12608Tampers with Border Gateway Protocol, DirectAccess, RemoteAccess or other VPN settings.
BH12609Tampers with BranchCache settings.
BH12610Tampers with certificates and certificate store.
BH12611Tampers with Cluster-Aware Updating.
BH12614Tampers with Computer Machine Password.
BH12615Tampers with Configurable Code Integrity settings.
BH12616Tampers with Control Panel items.
BH12617Tampers with cron jobs.
BH12618Tampers with Data Center Bridging (DCB) Quality of Service (QoS) settings.
BH12620Tampers with Developer Mode settings.
BH12621Tampers with Device Health Attestation (DHA) settings.
BH12623Tampers with Directory Certificate Services (AD CS) Certification Authority (CA).
BH12626Tampers with Display Resolution.
BH12627Tampers with Distributed File System (DFS) Namespaces.
BH12635Tampers with Dynamic Host Configuration Protocol (DHCP) server settings.
BH12636Tampers with Emergency Management Services (EMS).
BH12637Tampers with Emergency Management Services console settings.
BH12641Tampers with exploitation and security mitigation policies of a process.
BH12642Tampers with F10 key during startup to allow/prevent access to advanced boot menu.
BH12643Tampers with F8 key during startup to allow/prevent access to advanced boot menu.
BH12644Tampers with failed boot warning messages at startup.
BH12645Tampers with Failover Clustering.
BH12646Tampers with file extension associations.
BH12650Tampers with Group Policy Objects (GPOs) for a domain.
BH12651Tampers with Group Policy Objects dependencies.
BH12652Tampers with Group Policy settings.
BH12653Tampers with Host Guardian Service (HGS) Key Protection Service (KPS) settings.
BH12654Tampers with Host Guardian Service settings.
BH12657Tampers with Hyper-V Host Compute Service.
BH12658Tampers with Hyper-V Network Virtualization (HNV) settings.
BH12659Tampers with Hyper-V virtual machines.
BH12660Tampers with information in URL Zone Identifier, commonly used to bypass warnings after downloading files from the Internet.
BH12661Tampers with installed applications.
BH12662Tampers with Internet Information Services (IIS) settings.
BH12663Tampers with IP Address Management (IPAM) settings.
BH12668Tampers with Key Distribution Service (KDS) settings.
BH12673Tampers with macro options.
BH12674Tampers with Microsoft Distributed Transaction Coordinator (MSDTC) settings.
BH12675Tampers with Microsoft Excel settings.
BH12676Tampers with Microsoft Message Queuing.
BH12677Tampers with Microsoft User Experience Virtualization (UE-V) settings.
BH12679Tampers with Multipath I/O (MPIO) settings.
BH12681Tampers with network adapter settings.
BH12682Tampers with network adapters.
BH12683Tampers with Network Address Translation (NAT).
BH12685Tampers with Network Connectivity Status Indicator settings.
BH12686Tampers with Network Controller settings.
BH12687Tampers with Network File System (NFS) settings.
BH12689Tampers with Network Load Balancing (NLB) cluster settings.
BH12690Tampers with Network Logical Link Discovery Protocol.
BH12691Tampers with Network Policy Server (NPS) settings.
BH12693Tampers with Network Quality of Service (QoS) settings.
BH12696Tampers with Network Switch settings.
BH12697Tampers with Network Switch Team settings.
BH12698Tampers with Network Virtualization settings.
BH12699Tampers with NIC Teaming (load balancing and failover) settings.
BH12702Tampers with Open Database Connectivity (ODBC) drivers.
BH12703Tampers with password and logon restrictions.
BH12704Tampers with performance counters.
BH12712Changes printer settings.
BH12713Tampers with registry entries.
BH12714Tampers with Remote Desktop Licensing settings.
BH12715Tampers with Remote Desktop Service settings.
BH12721Tampers with Secure Boot settings.
BH12723Tampers with security or audit policies.
BH12724Tampers with Server Manager Tasks Configuration settings.
BH12726Tampers with Server Message Block (SMB) witness client registrations.
BH12730Tampers with Startup Repair (Automatic Repair) at startup.
BH12731Tampers with Storage Management Initiative - Specification (SMI-S) provider.
BH12732Tampers with Storage Pools.
BH12733Tampers with Storage Quality of Service (QoS) settings.
BH12734Tampers with Storage Replica settings.
BH12735Tampers with storage subsystem.
BH12738Tampers with system date.
BH12739Tampers with system environment variables.
BH12740Tampers with system firmware environment variables.
BH12743Tampers with system settings.
BH12749Tampers with the local computer name.
BH12751Tampers with the secure channel between the local computer and its domain.
BH12752Tampers with the workspace settings.
BH12753Tampers with Transport Layer Security (TLS) protocol cipher suites.
BH12754Tampers with Trusted Platform Module (TPM).
BH12756Tampers with User Access Logging.
BH12758Tampers with user logon screen.
BH12761Tampers with visibility settings.
BH12764Tampers with VPN Client settings.
BH12769Tampers with Windows Container networking settings.
BH12772Tampers with Windows features, roles or role services.
BH12773Tampers with Windows Firewall or IPsec settings.
BH12774Tampers with Windows Hardware Error Architecture memory policies.
BH12775Tampers with Windows MultiPoint Server desktops.
BH12778Tampers with Windows Search settings.
BH12779Tampers with Windows Server Backup settings.
BH12780Tampers with Windows Server Migration Tools.
BH12781Tampers with Windows Server Update Services.
BH12785Tampers with Windows Store apps.
BH12787Tampers with worksheet editing options.
BH12788Tampers with WS-Manager settings.
BH12790Temporarily disables power management.
BH12806Uses BCDboot command line tool.
BH12807Uses BCDedit command line tool.
BH12809Uses certutil command line tool.
BH12810Uses cmstp command line tool.
BH12819Verifies whether a TPM supports specified features.
BH12826Removes protection from the active sheet, macro sheet, chart, dialog sheet, module, or scenario.
BH12859Accesses a cron job file.
BH12872Modifies a group password.
BH12873Modifies a group name.
BH12874Modifies a group gid.
BH12875Removes a user from a group.
BH12908Modifies user groups.
BH12909Modifies the user home location.
BH12910Modifies the primary user group.
BH12911Locks the user account.
BH12912Modifies the user uid.
BH12913Modifies the user shell.
BH12914Modifies the user subuids/subgids.
BH12916Sets a gsettings value.
BH12920Sets the value of an sd-bus property.
BH12924Configues kernel parameters at runtime.
BH12945Allocates system users or groups.
BH12960Changes the ulimit configuration.
BH13018Adds an apt repository.
BH13037Changes a user's password expiry.
BH13038Changes a user's login shell.
BH13044Uses the Kerberos database maintenance utility.
BH13045Uses the Kerberos V5 database administration system.
BH13061Installs an XDG desktop file.
BH13062Sets file capabilities.
BH13076Manages devices of running Linux Containers.
BH13084Moves LXD instances within or in between LXD servers.
BH13087Manages LXD profiles.
BH13088Manages LXD projects.
BH13092Manages LXD storage pools and volumes.
BH13122Populates a dconf subpath.
BH13226Writes data to an SSH configuration file.
BH13253Creates or modifies an environment variable.
BH13259Deletes an environment variable.
BH13295Contains references to environment variables related to Amazon Web Services (AWS).
BH13296Contains a reference to an environment variable that holds an Amazon Web Services (AWS) access key.
BH13297Contains a reference to an environment variable that holds an Amazon Web Services (AWS) configuration location.
BH13298Contains a reference to an environment variable that holds an Amazon Web Services (AWS) secret access key.
BH13299Contains a reference to an environment variable that holds an Amazon Web Services (AWS) session token.
BH13300Contains a reference to an environment variable that holds an Amazon Web Services (AWS) access key location.
BH13301Contains a reference to an environment variable that holds an Amazon Web Services (AWS) web identity token location.
BH16142Creates a bitsadmin job.
BH16143Activates a bitsadmin job.
BH17299Modifies user profile settings.
BH18123Detects if the current operating system is Windows NT.
BH19114Enumerates audit policies.
BH19127Enumerates cached Kerberos tickets.
BH19134Enumerates TLS cipher suites for a computer.
BH19149Enumerates default load balance policy for MPIO devices.
BH19154Enumerates DFS namespace settings for a DFSN root server.
BH19160Enumerates DTC instances.
BH19161Enumerates Elliptic Curve Cryptography (ECC) cipher suites available for TLS for a computer.
BH19166Enumerates event triggers on local or remote machines.
BH19172Enumerates features of a network switch.
BH19183Enumerates information about Windows Server roles, role services, and features that are available for installation and installed on a specified server.
BH19190Enumerates IP addresses that need to be added and deleted to an IPsec rule.
BH19207Enumerates MPIO settings.
BH19213Enumerates network controller application settings.
BH19214Enumerates network controller cluster settings.
BH19215Enumerates network controller diagnostic settings.
BH19216Enumerates network controller node settings.
BH19222Enumerates NRPT global settings.
BH19233Enumerates permissions for a DFS namespace folder.
BH19245Enumerates products currently available on WSUS.
BH19257Enumerates running processes on a remote computer.
BH19261Enumerates scheduled tasks on a remote computer.
BH19262Enumerates scheduled tasks.
BH19270Enumerates settings for a DFS namespace folder.
BH19271Enumerates settings for DFS namespaces.
BH19272Enumerates settings for MSDSM automatically claiming SAN disks for MPIO.
BH19273Enumerates settings for root targets of a DFS namespace.
BH19274Enumerates settings for targets of a DFS namespace folder.
BH19298Enumerates team interfaces.
BH19332Enumerates values for the options that can be configured.
BH19336Enumerates Windows Container networking settings.
BH19343Gets a VIP resource.
BH19344Gets a virtual desktop.
BH19347Gets an object that contains information about a TPM.
BH19348Gets and writes the RSoP information for a user, a computer, or both to a file.
BH19349Gets BidTrace settings.
BH19352Gets data center bridging exchange settings.
BH19353Gets dynamic categories on a WSUS server.
BH19355Gets global data of a network switch.
BH19356Gets Group Policy inheritance information for a specified domain or OU.
BH19363Gets information about the endorsement key and certificates of the TPM.
BH19369Gets one GPO or all the GPOs in a domain.
BH19370Gets one or more Registry preference items under either Computer Configuration or User Configuration in a GPO.
BH19371Gets one or more registry-based policy settings under either Computer Configuration or User Configuration in a GPO.
BH19372Gets or sets the security protocol used by the ServicePoint objects.
BH19377Gets run-time information for a scheduled task.
BH19381Gets the active encryption certificate thumbprint.
BH19382Gets the active signing certificate.
BH19383Gets the attestation signer certificates that the Key Protection Service trusts.
BH19385Gets the certificate chain policy.
BH19387Gets the configuration of the Key Protection Service.
BH19393Gets the file information necessary to create AppLocker rules from a list of files or an event log.
BH19395Gets the inactive encryption certificate.
BH19396Gets the inactive signing certificate.
BH19398Gets the job options of scheduled jobs.
BH19401Gets the list of all WSUS classifications currently available in the system.
BH19402Gets the local, the effective, or a domain AppLocker policy.
BH19404Gets the object representing the policy store, which contains global QoS settings.
BH19405Gets the permission level for one or more security principals on a specified GPO.
BH19406Gets the prefix policy.
BH19407Gets the priority-based flow control settings.
BH19410Gets the security descriptor for a resource, such as a file or registry key.
BH19411Gets the set of all Windows features that can be migrated from the local server or from a migration store.
BH19412Gets the settings of the LLDP agent on a network interface on a host computer.
BH19417Gets the task definition object of a scheduled task that is registered on the local computer.
BH19418Gets the traffic class settings.
BH19420Gets the WSUS computer object that represents the client computer.
BH19421Gets the WSUS update object with details about the update.
BH19422Gets the WSUS update server object.
BH19423Gets trigger properties of a VPN connection.
BH19425Gets VIP host mapping.
BH19426Gets virtual network mapping.
BH19427Gets VLANs for a network switch.
BH19430Retrieves a storage QoS policy from the policy manager.
BH19433Retrieves certificate auto-enrollment policy settings.
BH19436Retrieves global DNS client settings like the suffix search list.
BH19447Retrieves the current configuration of the Microsoft Group KdsSvc from Active Directory.
BH20150Uses a Nishang command to modify Security Descriptors of DCOM and WMI namespaces to provide non-admin domain users access to WMI.
BH20151Uses a Nishang command to modify Security Descriptors of PowerShell Remoting to provide access for non-admin domain users.
BH20174Uses PowerSploit/Empire command to convert a given user/group name to a security identifier (SID).
BH20176Uses PowerSploit/Empire command to convert a UAC integer value to human readable form.
BH20177Uses PowerSploit/Empire command to convert Active Directory object names between a variety of formats.
BH20239Uses PowerSploit/Empire command to modify a given property for a specified Active Directory object.