Analytics BIOC Medium

Possible Persistence via group policy Registry keys

Group Policy registry keys were read during system startup. This behavior may indicate a persistence mechanism that triggers on reboot to execute malicious code.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
Attacker's goals:

Establish persistence on the host using Windows Group Policy mechanisms.

Investigative actions:

Inspect the registry keys and determine which process or command is configured to run. Verify whether the executing process is benign and expected as part of normal system behavior.

Test period:
N/A (single event)
Deduplication:
1 Day