Setting Windows Auto Logon by uncommon process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
Severity
Low
Description
Setting Windows Auto Logon by uncommon process.
Attacker's Goals
Adversary may attempt to set auto logon for persistence and privilege escalation.
Investigative actions
Investigate the process that set or create the registry key.
Was this helpful?
