Possible Persistence via group policy Registry keys
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
Severity
Medium
Description
Group Policy registry keys were read during system startup. This behavior may indicate a persistence mechanism that triggers on reboot to execute malicious code.
Attacker's Goals
Establish persistence on the host using Windows Group Policy mechanisms.
Investigative actions
Inspect the registry keys and determine which process or command is configured to run.
Verify whether the executing process is benign and expected as part of normal system behavior.
Was this helpful?
