Skip to content
Threat Feed
low advisory

Windows Registry Run Key Persistence Monitoring

Detection of unauthorized modifications to Windows registry autostart keys, a common technique used by threat actors to maintain persistence across system reboots.

Adversaries frequently achieve persistence on compromised Windows systems by modifying registry run keys to ensure their malicious code executes automatically upon user login or system startup. This technique, classified under MITRE ATT&CK as T1547.001, allows malware to re-establish access under the context of the affected user account. This brief focuses on detecting these modifications by monitoring specific, highly-abused registry paths including HKLM and HKEY_USERS run keys. While legitimate software installations, system updates, and administrative activities often modify these keys, unauthorized changes by non-standard processes are strong indicators of potential compromise. Defenders should establish a baseline of common installers and administrative tools to reduce noise while focusing on registry changes originating from unexpected processes or unsigned executables.

Impact

Successful exploitation allows attackers to maintain long-term access to compromised hosts, bypass traditional security controls that trigger only on initial execution, and execute secondary payloads in the context of user sessions. This persistence is a critical stage in the attack lifecycle for ransomware operations, data exfiltration, and long-term espionage campaigns.

Recommendation

  1. Deploy the provided Sigma rule to monitor registry modification events, focusing on the specific Run and RunOnce keys enumerated in the rule logic.
  2. Implement registry auditing (specifically process-level creation and modification events) to capture the parent process context for each modification.
  3. Integrate Osquery to perform ad-hoc hunting for unsigned services or suspicious persistence entries on hosts where a registry modification alert has fired.
  4. Perform baseline analysis to tune out legitimate installers (e.g., C:\Program Files, msiexec.exe) from the alerting path.

Immediate actions

Deploy registry monitoring rules for common autostart locations

Detection Engineering 72h

Threat Hunt

Search for unsigned executables referenced in Registry Run keys

T1547.001 medium medium confidence convert to detection

Data: Registry set events with process context

Detection coverage 1

Detect Suspicious Registry Run Key Modification

low

Detects modifications to Windows registry Run and RunOnce keys, often used for persistence.

sigma tactics: persistence techniques: T1547.001 sources: registry_set, windows

Detection queries are available on the platform. Get full rules →