Real-world descriptions of how a group, tool or campaign used a technique.
201 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
MalwareROADSWEEP | ROADSWEEP has been placed in the start up folder to trigger execution upon user login. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSysUpdate | SysUpdate can use a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTinyZBot | TinyZBot can create a shortcut in the Windows startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBoomBox | BoomBox can establish persistence by writing the Registry value |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareInnaputRAT | Some InnaputRAT variants establish persistence by modifying the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGrimAgent | GrimAgent can set persistence with a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLookBack | LookBack sets up a Registry Run key to establish a persistence mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePoetRAT | PoetRAT has added a registry key in the <RUN> hive for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFELIXROOT | FELIXROOT adds a shortcut file to the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBabyShark | BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
Malwarebuild_downer | build_downer has the ability to add itself to the Registry Run key for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareWinnti for Windows | Winnti for Windows can add a service named |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarenjRAT | njRAT has added persistence via the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMaze | Maze has created a file named "startup_vrun.bat" in the Startup folder of a virtual machine to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHIUPAN | HIUPAN has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTURNEDUP | TURNEDUP is capable of writing to a Registry Run key to establish. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareChChes | ChChes establishes persistence by adding a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareANDROMEDA | ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKOCTOPUS | KOCTOPUS can set the AutoRun Registry key with a PowerShell command. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHeyoka Backdoor | Heyoka Backdoor can establish persistence with the auto start function including using the value `EverNoteTrayUService`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHTTPBrowser | HTTPBrowser has established persistence by setting the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareOctopus | Octopus achieved persistence by placing a malicious executable in the startup directory and has added the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQilin | Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSTARWHALE | STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDownPaper | DownPaper uses PowerShell to add a Registry Run key in order to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCozyCar | One persistence mechanism used by CozyCar is to set itself to be executed at system startup by adding a Registry value under one of the following Registry keys: <br> |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAgent Tesla | Agent Tesla can add itself to the Registry as a startup program to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePOWERTON | POWERTON can install a Registry Run key for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBADNEWS | BADNEWS installs a registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRemexi | Remexi utilizes Run Registry keys in the HKLM hive as a persistence mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAstaroth | Astaroth creates a startup item for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQakBot | QakBot can maintain persistence by creating an auto-run Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHancitor | Hancitor has added Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGelsemium | Gelsemium can set persistence with a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHelminth | Helminth establishes persistence by creating a shortcut in the Start Menu folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareComnie | Comnie achieves persistence by adding a shortcut of itself to the startup path in the Registry. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareVasport | Vasport copies itself to disk and creates an associated run key Registry entry to establish. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBitPaymer | BitPaymer has set the run key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBACKSPACE | BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareADVSTORESHELL | ADVSTORESHELL achieves persistence by adding itself to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMivast | Mivast creates the following Registry entry: |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareWarzoneRAT | WarzoneRAT can add itself to the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UIF2IS20VK` Registry keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSmall Sieve | Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolSILENTTRINITY | SILENTTRINITY can establish a LNK file in the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolPowerSploit | PowerSploit's |
| T1547.001 Registry Run Keys / Startup Folder |
ToolEmpire | Empire can modify the registry run keys |
| T1547.001 Registry Run Keys / Startup Folder |
ToolRemcos | Remcos can add itself to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
ToolMCMD | MCMD can use Registry Run Keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolKoadic | Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolPupy | Pupy adds itself to the startup folder or adds itself to the Registry key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.