BIOC
Low
✕
Active Setup Registry Autostart
Suspicious modification of the active setup registry for persistence and privilege escalation.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Active Setup (T1547.014)
Indicator:
Registry action type = create_registry_key , set_registry_value AND registry data = *.dll AND registry key name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components AND registry value name = StubPath Host host os = windows
Preventable: yes