Analytics BIOC
Low
✕
Setting Windows Auto Logon by uncommon process
Setting Windows Auto Logon by uncommon process.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
Attacker's goals:
Adversary may attempt to set auto logon for persistence and privilege escalation.
Investigative actions:
Investigate the process that set or create the registry key.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day