BIOC
Informational
✕
New entry added to startup related Registry keys by unsigned process
Entries added to the "Run Keys" in the Registry or the startup folder will cause the program to be executed when the user logs in. The program will be executed in the context of the user and will have his permissions level.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
Indicator:
Registry action type = create_registry_key , rename_registry_key , set_registry_value AND registry key name = *software\Microsoft\Windows*CurrentVersion\run* , *Wow6432Node\Microsoft\Windows*CurrentVersion\Run* , *Software\Microsoft\Windows*CurrentVersion\Winlogon\Userinit* Process initiator signature = Unsigned , N/A , Invalid Signature , Weak Hash , cgo signature = Unsigned , N/A , Invalid Signature , Weak Hash Host host os = windows
Preventable: yes