1200KM / simulation
T1547.001 Registry Run Keys / Startup Folder — Attack Simulation
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level. The following run keys are created by default on Windows systems: *…
Technique description
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level. The following run keys are created by default on Windows systems: *…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- secedit used to create a Run key in the HKLM Hive
Procedure 14fdc3f1-6fc3-4556-8d36-aa89d9d42d02; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- HKLM - Modify default System Shell - Winlogon Shell KEY Value
Procedure 1d958c61-09c6-4d9e-b26b-4130314e520e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add Executable Shortcut Link to User Startup Folder
Procedure 24e55612-85f6-4bd6-ae74-a73d02e3441d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Suspicious vbs file run from startup Folder
Procedure 2cb98256-625e-4da9-9d44-f2e5f90b8bd5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Turla Mosquito Run Key Persistence via rundll32 DLL Export
Procedure 522c390e-8c86-497c-b37e-79a4eb072a89; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Reg Key RunOnce
Procedure 554cbd88-cde1-4b56-8168-0be552eed9eb; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Suspicious bat file run from startup Folder
Procedure 5b6768e4-44d2-44f0-89da-a01d1430fd5e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Creating Boot Verification Program Key for application execution during successful boot
Procedure 6e1666d5-3f2b-4b9a-80aa-f011322380d4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Change Startup Folder - HKCU Modify User Shell Folders Startup Value
Procedure 8834b65a-f808-4ece-ad7e-2acdf647aafa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- SystemBC Malware-as-a-Service Registry
Procedure 9dc7767b-30c1-4cc4-b999-50cab5e27891; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- HKCU - Policy Settings Explorer Run Key
Procedure a70faea1-e206-4f6f-8d9a-67379be8f6f1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Change Startup Folder - HKLM Modify User Shell Folders Common Startup Value
Procedure acfef903-7662-447e-a391-9c91c2f00f7b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Allowing custom application to execute during new RDP logon session
Procedure b051b3c0-66e7-4a81-916d-e6383bd3a669; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- HKLM - Policy Settings Explorer Run Key
Procedure b5c9a9bc-dda3-4ea0-b16a-add8e81ab75f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add persistance via Recycle bin
Procedure bda6a3d6-7aa7-4e89-908b-306772e9662f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Modify BootExecute Value
Procedure befc2b40-d487-4a5a-8813-c11085fb5672; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Suspicious jse file run from startup Folder
Procedure dade9447-791e-4c8f-b04b-3a35855dfa06; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add persistence via Windows Context Menu
Procedure de47f4a0-2acb-416d-9a6b-cee584a4c4d1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Reg Key Run
Procedure e55be3fd-3521-4610-9d1a-e210e42dcf05; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- PowerShell Registry RunOnce
Procedure eb44f842-0457-4ddc-9b92-c4caa144ac42; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- HKLM - Append Command to Winlogon Userinit KEY Value
Procedure f7fab6cc-8ece-4ca7-a0f1-30a22fccd374; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- APT29 · G0016
- Naikon · G0019
- Molerats · G0021
- APT3 · G0022
- Putter Panda · G0024
- APT18 · G0026
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Dragonfly · G0035
- FIN6 · G0037
- Patchwork · G0040
- FIN7 · G0046
- Gamaredon Group · G0047
- RTM · G0048
- APT32 · G0050
- FIN10 · G0051
- PROMETHIUM · G0056
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- APT33 · G0064
- Leviathan · G0065
- APT37 · G0067
- MuddyWater · G0069
- Dark Caracal · G0070
- APT19 · G0073
- Gorgon Group · G0078
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT39 · G0087
- Silence · G0091
- Kimsuky · G0094
- APT41 · G0096
- Inception · G0100
- Wizard Spider · G0102
- Rocke · G0106
- Windshift · G0112
- Sidewinder · G0121
- Higaisa · G0126
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- TeamTNT · G0139
- LazyScripter · G0140
- Confucius · G0142
- LuminousMoth · G1014
- FIN13 · G1016
- TA2541 · G1018
- Moonstone Sleet · G1036
- RedCurl · G1039
- BlackByte · G1043
- Storm-1811 · G1046
- Contagious Interview · G1052
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.