Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Persistence, Privilege Escalation

T1547.001 Registry Run Keys / Startup Folder

Sub-technique of T1547 Boot or Logon Autostart Execution

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in.(Citation: Microsoft Run Key) These programs will be executed under the context of the user and will have the account's associated permissions…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Showing 25 of 38.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.