Classic path: registry Run Keys
The act of including an entry within the Run Keys
file located in the registry will result in the automatic execution of the referred application upon a user’s login. The execution of these applications will occur within the user’s context and will be subject to the permissions level associated with the user’s account.
By default, Windows Systems generate the following run keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
Threat actors have the capability to take advantage of those mentioned configuration locations as a means to run malware, hence ensuring the continuity of their presence within a system even after reboot. Threat actors may employ masquerade techniques to create the illusion that registry...