Autorun or ASEP Registry Key Modification

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Adversaries and malware persist by adding a program to the startup folder or a Registry run key, so it runs at user logon. Run keys have legitimate uses, but malicious entries often have random names or load objects from temp or public folders.

Attribute Value
Type Hunting Query
Solution Intel471
ID 8289e2ad-bc74-4ae3-bfaa-cdeb4335135c
Tactics Persistence, PrivilegeEscalation
Techniques T1547.001
Required Connectors SecurityEvents, WindowsSecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
SecurityEvent NewValue contains "\\ProgramData\\Package Cache\\"
NewValue has_any "\\Windows\\System32\\ctfmon.exe"
ObjectName has_any "\\software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders"
ObjectName has_any "\\software\\Microsoft\\Windows\\CurrentVersion\\Run"
ObjectValueName has_any "\\Microsoft Visual Studio\\Installer\\"
ParentProcessName has_any "Program Files (x86)\\Microsoft\\Edge\\Application"
ParentProcessName has_any "vc_redist.x86.exe"
✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries · Back to Intel471