QuestionQ31

Threat Hunting Techniques

A security analyst needs to create a SIEM signature that detects malware modifying registry keys to establish persistence, ensuring the malware runs whenever a user signs in to Windows. The focus must be on specific registry changes linked to this persistence mechanism.

Which registry modification must the security analyst target?

Explanation

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run is the per-user Windows Run key. Entries in this key cause a program to run each time that user logs on, making it a standard logon-persistence location. RunOnce is unsuitable because it runs only once and is then removed.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!