Title:Potential Persistence Via Logon Scripts - CommandLine Status:test Description:Detects the addition of a new LogonScript to the registry value "UserInitMprLogonScript" for potential persistence References: -https://cocomelonc.github.io/persistence/2022/12/09/malware-pers-20.html Author: Tom Ueltschi (@c_APT_ure) Date: 2019-01-12 modified:2023-06-09 Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.t1037.001'
Logsource:
category: process_creation
product: windows
Detection: selection: CommandLine|contains:
'UserInitMprLogonScript' condition:selection Falsepositives:
-Legitimate addition of Logon Scripts via the command line by administrators or third party tools Level:high