Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0312 — Detect Active Setup Persistence via StubPath Execution
DET0312

Detect Active Setup Persistence via StubPath Execution

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0871 Analytic 0871
Windows

Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login.

WinEventLog:Security EventCode=4672 WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=12
[TimeWindow] Correlate registry change and process execution within a specific user logon session (e.g., 5–10 minutes)
[ParentProcessName] Expected parent processes for Active Setup launched binaries (e.g., explorer.exe). Deviations may indicate abuse.
[StubPathValueEntropy] Degree of randomness/uncommonness in StubPath values. High entropy may indicate obfuscation.
[SignedBinaryStatus] Flag if launched binary in StubPath is unsigned or uncommon for baseline
[RegistryKeyOwner] Check which user/context added the Active Setup key to detect privilege abuse

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0312
STIX ID
x-mitre-detection-strategy--ba8d3a5d-9ddc-4301-b021-84ca2c6854de
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.