QuestionQ11

Threat Hunting Techniques

Refer to the exhibit.

Question Image

An analyst is evaluating artifacts and logs collected from a recent breach. In the logs, ATP established malware persistence by placing a path to the executable in a specific registry entry.

What distinguishes the ATP’s approach from using HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run instead?

Explanation

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run is a per-user startup location, whereas the machine-wide HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run location generally requires administrative privileges to modify. Malware running without elevation can therefore establish persistence for the current user through the HKCU Run key.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!