1200KM / simulation
T1547.014 Active Setup — Attack Simulation
Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine. Active Setup is a Windows mechanism that is used to execute programs when a user logs in. The value stored in the Registry key will be executed after a user logs into the computer. These programs will be executed under the context of the user and will have the account's associated permissions level. Adversaries may abuse Active Setup by…
Technique description
Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine. Active Setup is a Windows mechanism that is used to execute programs when a user logs in. The value stored in the Registry key will be executed after a user logs into the computer. These programs will be executed under the context of the user and will have the account's associated permissions level. Adversaries may abuse Active Setup by…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- HKLM - re-execute 'Internet Explorer Core Fonts' StubPath payload by decreasing version number
Procedure 04d55cef-f283-40ba-ae2a-316bc3b5e78c; elevation required; cleanup not declared. Not executed or individually validated.
- HKLM - Add malicious StubPath value to existing Active Setup Entry
Procedure 39e417dd-4fed-4d9c-ae3a-ba433b4d0e9a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- HKLM - Add atomic_test key to launch executable as part of user setup
Procedure deff4586-0517-49c2-981d-bbea24d48d71; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.