BIOC
Informational
✕
Manipulation of Winlogon 'Notify' autostart Registry key
Since Winlogon handles the Secure Attention Sequence (SAS) (Ctrl+Alt+Del), notify subkeys found at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify are used to notify event handles when SAS happens and load a DLL. This DLL can be edited to launch whenever such a SAS event occurs.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Winlogon Helper DLL (T1547.004)
Indicator:
Registry action type = all AND registry key name = *\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify Host host os = windows
Preventable: yes