An uncommon file added to startup-related Registry keys
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Boot or Logon Autostart Execution (T1547)
Severity
Informational
Description
An attacker may add a file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in.
Attacker's Goals
Gain persistence using the legitimate Windows registry run key mechanism, which executes files or scripts on user login or computer boot.
Investigative actions
Verify if the registered file is malicious.
Check if the installing software is a malicious binary or script.
Variations
PreviousAn uncommon executable was remotely written over SMB to an uncommon destination
NextAn uncommon file was created in the startup folder
Was this helpful?
