LegacyHive: Offline Registry Hive Load Preceding SYSTEM Execution
Detects the loading of registry hives using the 'reg load' command. This technique is often associated with adversary attempts to manipulate the Windows registry, access sensitive data, or establish persistence, particularly when followed by actions executed in the SYSTEM context from the same process lineage.
Microsoft Sentinel (KQL)

