BigHugger
sk Skill · mukul975

hunting-for-registry-persistence-mechanisms

Hunts for registry-based persistence mechanisms (MITRE T1547) in Windows environments, including Run/RunOnce keys, Winlogon Shell/Userinit modifications, Image File Execution Options (IFEO) debugger injection, and COM hijacking via CLSID overrides. Use when auditing the registry for persistence artifacts or building detections for registry-based malware autostart techniques.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonproactive-detectionpersistencet1547windowsregistrymitre-attackthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python