1200KM / detection
T1547.001 Registry Run Keys / Startup Folder — Detection Rules
Detection workspace for T1547.001 Registry Run Keys / Startup Folder: 31 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- File Creation In Suspicious Directory By Msdt.EXE · test · high · {"category":"file_event","product":"windows"}
- Potential Startup Shortcut Persistence Via PowerShell.EXE · test · high · {"product":"windows","category":"file_event"}
- Startup Folder File Write · test · medium · {"product":"windows","category":"file_event"}
- Suspicious Startup Folder Persistence · test · high · {"product":"windows","category":"file_event"}
- WinRAR Creating Files in Startup Locations · experimental · high · {"category":"file_event","product":"windows"}
- Suspicious Autorun Registry Modified via WMI · experimental · high · {"category":"process_creation","product":"windows"}
- Potential Persistence Attempt Via Run Keys Using Reg.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Direct Autorun Keys Modification · test · medium · {"category":"process_creation","product":"windows"}
- Potential Suspicious Activity Using SeCEdit · test · medium · {"category":"process_creation","product":"windows"}
- User Shell Folders Registry Modification via CommandLine · experimental · high · {"category":"process_creation","product":"windows"}
- Narrator's Feedback-Hub Persistence · test · high · {"category":"registry_event","product":"windows"}
- Suspicious Run Key from Download · test · high · {"category":"registry_event","product":"windows"}
- Classes Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- Common Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- CurrentControlSet Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- CurrentVersion Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- CurrentVersion NT Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- Internet Explorer Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- Office Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- Session Manager Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- System Scripts Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- WinSock2 Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- Wow6432Node CurrentVersion Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- Wow6432Node Classes Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- Wow6432Node Windows NT CurrentVersion Autorun Keys Modification · test · medium · {"category":"registry_set","product":"windows"}
- Windows Event Log Access Tampering Via Registry · experimental · high · {"category":"registry_set","product":"windows"}
- Suspicious PowerShell In Registry Run Keys · test · medium · {"category":"registry_set","product":"windows"}
- Registry Persistence via Explorer Run Key · test · high · {"category":"registry_set","product":"windows"}
- New RUN Key Pointing to Suspicious Folder · experimental · high · {"category":"registry_set","product":"windows"}
- Modify User Shell Folders Startup Value · test · high · {"product":"windows","category":"registry_set"}
- VBScript Payload Stored in Registry · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
T1547.001 Registry Run Keys / Startup Folder
MATCH(registry_or_startup_path IN autostart_locations) AND executable NOT_IN approved_autostart_programs -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0365 Detect Registry and Startup Folder Persistence (Windows)
AN1032 Analytic 1032
Correlation of Registry key creation/modification events under known Run/Startup keys with new or unusual binary paths or script-based payloads. Multi-event detection includes registry modification followed by process execution from non-standard directories or abnormal parent-child process relationships.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- APT29 · G0016
- Naikon · G0019
- Molerats · G0021
- APT3 · G0022
- Putter Panda · G0024
- APT18 · G0026
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Dragonfly · G0035
- FIN6 · G0037
- Patchwork · G0040
- FIN7 · G0046
- Gamaredon Group · G0047
- RTM · G0048
- APT32 · G0050
- FIN10 · G0051
- PROMETHIUM · G0056
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- APT33 · G0064
- Leviathan · G0065
- APT37 · G0067
- MuddyWater · G0069
- Dark Caracal · G0070
- APT19 · G0073
- Gorgon Group · G0078
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT39 · G0087
- Silence · G0091
- Kimsuky · G0094
- APT41 · G0096
- Inception · G0100
- Wizard Spider · G0102
- Rocke · G0106
- Windshift · G0112
- Sidewinder · G0121
- Higaisa · G0126
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- TeamTNT · G0139
- LazyScripter · G0140
- Confucius · G0142
- LuminousMoth · G1014
- FIN13 · G1016
- TA2541 · G1018
- Moonstone Sleet · G1036
- RedCurl · G1039
- BlackByte · G1043
- Storm-1811 · G1046
- Contagious Interview · G1052
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.