BIOC
Informational
✕
Modification of default Windows startup path via Registry
An attacker may modify the startup path to the location of the malware.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
Indicator:
Registry registry key name = *microsoft\windows\currentversion\explorer\user shell folders* , *microsoft\windows\currentversion\explorer\shell folders* AND registry data != *Microsoft\Windows\Start Menu\Programs\Startup* AND *\users\*\start Menu\Programs\Startup* AND *%USERPROFILE%\start Menu\Programs\Startup* AND registry value name = startup AND action type = set_registry_value Process initiator signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash AND initiator signer != Citrix Systems, Inc. AND VMware, Inc. AND initiator cmd != *regsvr32.exe*/s*/n*/i:u*shell32.dll* Host host os = windows
Preventable: yes