Registry Run Keys / Startup Folder

T1547.001

Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org

About this technique

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

The following run keys are created by default on Windows systems:

* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce

Run keys may exist under multiple hives. The HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx is also available but is not created by default on Windows Vista and newer. Registry run key entries can reference programs directly or list them as a dependency. For example, it is possible to load a DLL at logon using a "Depend" key with RunOnceEx: reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\0001\Depend /v 1 /d "C:\temp\evil[.]dll"

Placing a program within a startup folder will also cause that program to execute when a user logs in. There is a startup folder location for individual user accounts as well as a system-wide startup folder that will be checked regardless of which user account logs in. The startup folder path for the current user is C:\Users\\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup. The startup folder path for all users is C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp.

The following Registry keys can be used to set startup folder items for persistence:

* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

The following Registry keys can control automatic startup of services during boot:

* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices

Using policy settings to specify startup programs creates corresponding values in either of two Registry keys:

* HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

Programs listed in the load value of the registry key HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows run automatically for the currently logged-on user.

By default, the multistring BootExecute value of the registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager is set to autocheck autochk *. This value causes Windows, at startup, to check the file-system integrity of the hard disks if the system has been shut down abnormally. Adversaries can add other programs or processes to this registry value which will automatically launch at boot.

Adversaries can use these configuration locations to execute malware, such as remote access tools, to maintain persistence through system reboots. Adversaries may also use Masquerading to make the Registry entries look as if they are associated with legitimate programs.

Detection rules37

Rules on DetectionCode tagged with T1547.001.

Sigma31

RuleLevelLog source
File Creation In Suspicious Directory By Msdt.EXEhighwindows / file_event
Modify User Shell Folders Startup Valuehighwindows / registry_set
Narrator's Feedback-Hub Persistencehighwindows / registry_event
New RUN Key Pointing to Suspicious Folderhighwindows / registry_set
Potential Startup Shortcut Persistence Via PowerShell.EXEhighwindows / file_event
Registry Persistence via Explorer Run Keyhighwindows / registry_set
Suspicious Autorun Registry Modified via WMIhighwindows / process_creation
Suspicious Run Key from Downloadhighwindows / registry_event
Suspicious Startup Folder Persistencehighwindows / file_event
User Shell Folders Registry Modification via CommandLinehighwindows / process_creation
VBScript Payload Stored in Registryhighwindows / registry_set
Windows Event Log Access Tampering Via Registryhighwindows / registry_set
WinRAR Creating Files in Startup Locationshighwindows / file_event
Classes Autorun Keys Modificationmediumwindows / registry_set
Common Autorun Keys Modificationmediumwindows / registry_set

Splunk6

RuleTypeRiskData source
Registry Keys Used For PersistenceTTPNULLSysmon EventID 13
Windows Boot or Logon Autostart Execution In Startup FolderAnomalyNULLSysmon EventID 11
Windows NorthStar C2 Agent ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows PowerShell MSIX Package InstallationTTPNULLPowershell Script Block Logging 4104
Windows Registry BootExecute ModificationTTPNULLSysmon EventID 13
Windows Registry Modification for Safe Mode PersistenceTTPNULLSysmon EventID 13

Groups57

Show 33 more

Software201

Show 177 more

Campaigns3

Procedure examples261

Groups57

Used byProcedure example
GroupAPT18

APT18 establishes persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key.

GroupAPT19

An APT19 HTTP malware variant establishes persistence by setting the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Debug Tools-%LOCALAPPDATA%\.

GroupAPT28

APT28 has deployed malware that has copied itself to the startup directory for persistence.

GroupAPT29

APT29 added Registry Run keys to establish persistence.

GroupAPT3

APT3 places scripts in the startup folder for persistence.

GroupAPT32

APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly.

GroupAPT33

APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence.

GroupAPT37

APT37's has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\.

View all 57 groups examples

Software201

Used byProcedure example
MalwareADVSTORESHELL

ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

MalwareAgent Tesla

Agent Tesla can add itself to the Registry as a startup program to establish persistence.

MalwareAmadey

Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys.

MalwareANDROMEDA

ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on.

MalwareAppleSeed

AppleSeed has the ability to create the Registry key name EstsoftAutoUpdate at HKCU\Software\Microsoft/Windows\CurrentVersion\RunOnce to establish persistence.

MalwareAria-body

Aria-body has established persistence via the Startup folder or Run Registry key.

MalwareAstaroth

Astaroth creates a startup item for persistence.

MalwareAuTo Stealer

AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence.

View all 201 software examples

Campaigns3

Used byProcedure example
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence.

CampaignOperation Sharpshooter

During Operation Sharpshooter, a first-stage downloader installed Rising Sun to `%Startup%\mssync.exe` on a compromised host.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used Run registry keys with names such as `OneNote Update` to execute legitimate executables that would load through search-order hijacking malicious DLLS to ensure persistence during RedDelta Modified PlugX Infection Chain Operations.

References4

  1. Malwarebytes Wow6432Node 2016 Open source
    Arntz, P. (2016, March 30). Hiding in Plain Sight. Retrieved August 3, 2020.
  2. Microsoft Run Key Open source
    Microsoft. (n.d.). Run and RunOnce Registry Keys. Retrieved September 12, 2024.
  3. Microsoft Wow6432Node 2018 Open source
    Microsoft. (2018, May 31). 32-bit and 64-bit Application Data in the Registry. Retrieved August 3, 2020.
  4. Oddvar Moe RunOnceEx Mar 2018 Open source
    Moe, O. (2018, March 21). Persistence using RunOnceEx - Hidden from Autoruns.exe. Retrieved June 29, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.