Potential Persistence Via Logon Scripts - CommandLine

 Original Source: [Sigma source]
Title: Potential Persistence Via Logon Scripts - CommandLine
Status: test
Description:Detects the addition of a new LogonScript to the registry value "UserInitMprLogonScript" for potential persistence
References:
  -https://cocomelonc.github.io/persistence/2022/12/09/malware-pers-20.html
Author: Tom Ueltschi (@c_APT_ure)
Date: 2019-01-12
modified:2023-06-09
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1037.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains: 'UserInitMprLogonScript'
  condition:selection
Falsepositives:
  -Legitimate addition of Logon Scripts via the command line by administrators or third party tools
Level: high