Registry Run Keys / Startup Folder
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in.(Citation: Microsoft Run Key) These programs will be executed under the context of the user and will have the account's associated permissions level. The following run keys are created by default on Windows systems: * <code>HKEY_CURRENT_USER\...
BY SOURCE
PROCEDURES (23)
Auto-extracted: 14 detections for registry
Auto-extracted: 3 detections for startup
Auto-extracted: 3 detections for suspicious
Auto-extracted: 3 detections for suspicious
Auto-extracted: 3 detections for persist
Auto-extracted: 3 detections for startup
Auto-extracted: 2 detections for startup
Auto-extracted: 2 detections for service
Auto-extracted: 2 detections for tamper
Auto-extracted: 2 detections for registry monitoring
Auto-extracted: 1 detections for bypass
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for bypass
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for registry
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for startup
Auto-extracted: 1 detections for startup
Auto-extracted: 1 detections for powershell