For the complete documentation index, see llms.txt. This page is also available as Markdown.

Possible Persistence via group policy Registry keys

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)

Severity

Medium

Description

Group Policy registry keys were read during system startup. This behavior may indicate a persistence mechanism that triggers on reboot to execute malicious code.

Attacker's Goals

Establish persistence on the host using Windows Group Policy mechanisms.

Investigative actions

  • Inspect the registry keys and determine which process or command is configured to run.

  • Verify whether the executing process is benign and expected as part of normal system behavior.

Was this helpful?