Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1547.001

T1547.001Registry Run Keys / Startup Folder

T1547.001 — Registry Run Keys / Startup Folder is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 39 detection use cases covering it and 22 threat-intel articles citing it.

PersistencePrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
39Use cases
22Articles
0Sub-techniques
2Tactics

Use cases covering this technique (39)

Registry Keys Used For Persistence ESCU actions · alerting P Windows Boot or Logon Autostart Execution In Startup Folder ESCU actions · hunting P Windows NorthStar C2 Agent Execution ESCU actions · alerting P Windows PowerShell MSIX Package Installation ESCU actions · alerting P Windows Registry BootExecute Modification ESCU actions · alerting P Windows Registry Modification for Safe Mode Persistence ESCU actions · alerting P [LLM] File writes to sensitive paths by LangGraph Python/Node runtime Bespoke actions · hunting DSΣPDDCS [LLM] Registry Run-key persistence written by SPECTRALVIPER side-load chain Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine Bespoke exploit · hunting DSP [LLM] WinRAR CVE-2025-8088 — archive tool writes payload to user Startup folder Bespoke install · alerting DSΣPDDCS [LLM] Startup LNK spawns cmd.exe → PowerShell in-memory DLL loader (GIFTEDCROOK chain) Bespoke install · alerting DSPDDCS [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a Bespoke exploit · hunting DSP [LLM] PowerShower dropped to user Pictures folder as googleearth.ps1 Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Tracking TamperedChef Clusters via Certificate and Code Reuse Bespoke exploit · hunting DSP Article-specific behavioural hunt — Webworm: New burrowing techniques Bespoke exploit · hunting DSP Article-specific behavioural hunt — Webworm: New burrowing techniques Bespoke exploit · hunting DSP [LLM] Apache Camel JVM writing files to sensitive paths via camel-file (CVE-2026-47323 arbitrary file write) Bespoke install · hunting DSPDDCS Article-specific behavioural hunt — Kimsuky targets organizations with PebbleDash-based tools Bespoke exploit · hunting DSP [LLM] Kimsuky HelloDoor 'tdll' Run-key persistence with regsvr32 loader Bespoke install · alerting DSΣPDD [LLM] Kimsuky httpMalice persistence: 'Everything 1.9a-/1.8a-' Run-key or CacheDB service install Bespoke install · alerting DSPDD Article-specific behavioural hunt — FrostyNeighbor: Fresh mischief and digital shenanigans Bespoke exploit · hunting DSP Article-specific behavioural hunt — FrostyNeighbor: Fresh mischief and digital shenanigans Bespoke exploit · hunting DSP [LLM] IoliteLabs Stage-2 regsvr32 LOLbin loading ntuser DLL from fake Chrome\ChromeUpdate path Bespoke install · alerting DSΣPDD Article-specific behavioural hunt — TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package Bespoke exploit · hunting DSP [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Popular telnyx package compromised on PyPI by TeamPCP Bespoke exploit · hunting DSP [LLM] TeamPCP msbuild.exe persistence in user Startup folder Bespoke install · alerting DSΣPDDCS [LLM] ValleyRAT registry-resident shellcode (HKCU\Console\0|1) and MyPythonApp Run-key persistence Bespoke install · hunting DSΣP Article-specific behavioural hunt — GlassWorm Hides a RAT Inside a Malicious Chrome Extension Bespoke exploit · hunting DSP [LLM] GlassWorm Stage-3 RAT installation under %APPDATA%\QtCvyfVWKH\index.js Bespoke install · alerting DSΣPDDCS [LLM] GlassWorm Stage-3a UpdateLedger Run-key persistence pointing at %TEMP%\SKuyzYcDD.exe Bespoke install · alerting DSΣPDDCS [LLM] Glassworm stage-3 persistence: schtasks UpdateApp + HKCU Run DPKCbbQ Bespoke install · alerting DSΣPDD [LLM] DRILLAPP variant 1 persistence: LNK file written to user Startup folder by non-Explorer process Bespoke install · alerting DSΣPDDCS [LLM] PlugX persistence — Run key 'G DATA' pointing to C:\Users\Public\GDatas\Avk.exe Bespoke install · alerting DSΣPDDCS [LLM] MuddyViper persistence via ManageOnDriveUpdater scheduled task or Startup folder hijack Bespoke install · alerting DSPDDCS [LLM] WinRAR CVE-2025-8088 path traversal — payload dropped to user Startup folder Bespoke install · alerting DSΣPDDCS [LLM] Archive utility writing LNK/DLL/EXE to Windows Startup folder (RomCom CVE-2025-8088) Bespoke install · alerting DSΣP [LLM] SnakeStealer Startup-Folder Persistence (ageless.vbs / .exe drop in Programs\Startup) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (22)