T1547.001 Registry Run Keys / Startup Folder
Sub-technique of T1547 Boot or Logon Autostart Execution
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in.(Citation: Microsoft Run Key) These programs will be executed under the context of the user and will have the account's associated permissions…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Leviathan Registry Key Activitycriticaltest · windows
- Potential Ryuk Ransomware Activityhighstable · windows
- File Creation In Suspicious Directory By Msdt.EXEhightest · windows
- Forest Blizzard APT - Custom Protocol Handler Creationhightest · windows
- Forest Blizzard APT - Custom Protocol Handler DLL Registry Sethightest · windows
- Kapeka Backdoor Autorun Persistencehightest · windows
- Modify User Shell Folders Startup Valuehightest · windows
- Narrator's Feedback-Hub Persistencehightest · windows
- Potential KamiKakaBot Activity - Winlogon Shell Persistencehightest · windows
- Potential Startup Shortcut Persistence Via PowerShell.EXEhightest · windows
- Registry Persistence via Explorer Run Keyhightest · windows
- Suspicious Run Key from Downloadhightest · windows
- Suspicious Startup Folder Persistencehightest · windows
- Suspicious VBScript UN2452 Patternhightest · windows
- VBScript Payload Stored in Registryhightest · windows
- New RUN Key Pointing to Suspicious Folderhighexperimental · windows
- Suspicious Autorun Registry Modified via WMIhighexperimental · windows
- User Shell Folders Registry Modification via CommandLinehighexperimental · windows
- WinRAR Creating Files in Startup Locationshighexperimental · windows
- Windows Event Log Access Tampering Via Registryhighexperimental · windows
- Classes Autorun Keys Modificationmediumtest · windows
- Common Autorun Keys Modificationmediumtest · windows
- CurrentControlSet Autorun Keys Modificationmediumtest · windows
- CurrentVersion Autorun Keys Modificationmediumtest · windows
- CurrentVersion NT Autorun Keys Modificationmediumtest · windows
Showing 25 of 38.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.