BIOC
Medium
✕
Manipulation of the MonitorProcess Registry key
Entries added under the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit can be used to run malicious code and help attackers gain persistence.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Event Triggered Execution: Image File Execution Options Injection (T1546.012)
Indicator:
Registry action type = create_registry_key , set_registry_value AND registry key name = *silentprocessexit* AND registry value name = monitorprocess Host host os = windows
Preventable: yes