1200KM / detection
T1547.014 Active Setup — Detection Rules
Detection workspace for T1547.014 Active Setup: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potential Suspicious Activity Using SeCEdit · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0312 Detect Active Setup Persistence via StubPath Execution
AN0871 Analytic 0871
Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1547.014 simulation workspace
- Logon Session Metadata · DC0088
- Process Creation · DC0032
- Windows Registry Key Creation · DC0056
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.