Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0365 — Detect Registry and Startup Folder Persistence (Windows)
DET0365

Detect Registry and Startup Folder Persistence (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1032 Analytic 1032
Windows

Correlation of Registry key creation/modification events under known Run/Startup keys with new or unusual binary paths or script-based payloads. Multi-event detection includes registry modification followed by process execution from non-standard directories or abnormal parent-child process relationships.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Microsoft-Windows-Shell-Core New startup folder shortcut or binary placed in Startup directory
[ImagePath] Full path of the binary/script being registered in Run keys. Tunable to exclude known software baselines.
[RegistryKeyPath] Tunable list of startup-related registry keys to monitor more/less aggressively based on enterprise software context.
[TimeWindow] Correlate registry key creation and process execution within this window. Defaults between 5–10 minutes.
[UserContext] Filter for specific user SIDs or exclude known admin/script accounts.

Detected Techniques

1

Details

MITRE ID
DET0365
STIX ID
x-mitre-detection-strategy--8febbfe8-91ae-4625-8fc7-656639b90a11
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.