Windows Registry Run Key Persistence Monitoring
Detection of unauthorized modifications to Windows registry autostart keys, a common technique used by threat actors to maintain persistence across system reboots.
Adversaries frequently achieve persistence on compromised Windows systems by modifying registry run keys to ensure their malicious code executes automatically upon user login or system startup. This technique, classified under MITRE ATT&CK as T1547.001, allows malware to re-establish access under the context of the affected user account. This brief focuses on detecting these modifications by monitoring specific, highly-abused registry paths including HKLM and HKEY_USERS run keys. While legitimate software installations, system updates, and administrative activities often modify these keys, unauthorized changes by non-standard processes are strong indicators of potential compromise. Defenders should establish a baseline of common installers and administrative tools to reduce noise while focusing on registry changes originating from unexpected processes or unsigned executables.
Impact
Successful exploitation allows attackers to maintain long-term access to compromised hosts, bypass traditional security controls that trigger only on initial execution, and execute secondary payloads in the context of user sessions. This persistence is a critical stage in the attack lifecycle for ransomware operations, data exfiltration, and long-term espionage campaigns.
Recommendation
- Deploy the provided Sigma rule to monitor registry modification events, focusing on the specific Run and RunOnce keys enumerated in the rule logic.
- Implement registry auditing (specifically process-level creation and modification events) to capture the parent process context for each modification.
- Integrate Osquery to perform ad-hoc hunting for unsigned services or suspicious persistence entries on hosts where a registry modification alert has fired.
- Perform baseline analysis to tune out legitimate installers (e.g., C:\Program Files, msiexec.exe) from the alerting path.
Immediate actions
Deploy registry monitoring rules for common autostart locations
Threat Hunt
Search for unsigned executables referenced in Registry Run keys
Data: Registry set events with process context
Detection coverage 1
Detect Suspicious Registry Run Key Modification
lowDetects modifications to Windows registry Run and RunOnce keys, often used for persistence.
Detection queries are available on the platform. Get full rules →