An uncommon file was created in the startup folder
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
7 Days
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
Severity
Informational
Description
An uncommon file was created in the startup folder.
Attacker's Goals
Maintain persistence on the host through automatic execution at startup.
Investigative actions
Determine if the file was created as part of a legitimate application installation, and check other files written by the same process.
Identify which program opens this file based on its extension.
Check the registry at HKEY_CLASSES_ROOT[extension]\shell[action]\command to see the default application or command used to execute the file.
Variations
Was this helpful?
