Script file added to startup-related Registry keys
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Boot or Logon Autostart Execution (T1547)
Severity
Medium
Description
An attacker may add a script file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in.
Attacker's Goals
Gain persistence using the legitimate Windows registry run key mechanism, which executes commands on user login or computer boot.
Investigative actions
Verify if the registered script is malicious.
Check if the installed software is a malicious binary or script.
PreviousScreensaver process executed from Users or temporary folder
NextScripting engine connected to a rare external host
Was this helpful?
