T1547.001Registry Run Keys / Startup Folder
T1547.001 — Registry Run Keys / Startup Folder is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 34 detection use cases covering it and 19 threat-intel articles citing it.
PersistencePrivilege Escalation
34Use cases
19Articles
0Sub-techniques
2Tactics
↑ Parent technique: T1547 · Boot or Logon Autostart Execution
Use cases covering this technique (34)
Registry Keys Used For Persistence Windows Boot or Logon Autostart Execution In Startup Folder Windows NorthStar C2 Agent Execution Windows PowerShell MSIX Package Installation Windows Registry BootExecute Modification Windows Registry Modification for Safe Mode Persistence [LLM] CoolClient persistence: 'goopdate' Run key and 'media_updaten' service creation Article-specific behavioural hunt — New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure [LLM] PATCHCORD 'BeaconBrowserHijack' Run-key persistence (APT36) [LLM] SHEETCORD VBS Startup-folder persistence drop Article-specific behavioural hunt — The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Co Article-specific behavioural hunt — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware deliver [LLM] CornFlake RAT persistence via svchost32.exe masquerade in %APPDATA% Article-specific behavioural hunt — UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially [LLM] axios RAT persistence: HKCU Run value MicrosoftUpdate pointing to system.bat [LLM] Gamaredon WinRAR CVE-2025-8088 ADS path-traversal dropping HTA/VBS into Startup folder [LLM] Gamaredon HTA downloader auto-executing from Startup folder at logon (mshta.exe) [LLM] easy-day-js Windows persistence: Run key 'NvmProtocal' / protocal.cjs autostart [LLM] easy-day-js implant artifacts dropped: protocal.cjs / NodePackages / cross-OS persistence files Article-specific behavioural hunt — ESET takes part in Operation Endgame to disrupt Amadey and Stealc Article-specific behavioural hunt — ESET takes part in Operation Endgame to disrupt Amadey and Stealc [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Article-specific behavioural hunt — Webworm: New burrowing techniques Article-specific behavioural hunt — Webworm: New burrowing techniques Article-specific behavioural hunt — FrostyNeighbor: Fresh mischief and digital shenanigans Article-specific behavioural hunt — FrostyNeighbor: Fresh mischief and digital shenanigans [LLM] IoliteLabs Stage-2 regsvr32 LOLbin loading ntuser DLL from fake Chrome\ChromeUpdate path Article-specific behavioural hunt — TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) [LLM] ValleyRAT registry-resident shellcode (HKCU\Console\0|1) and MyPythonApp Run-key persistence [LLM] DRILLAPP variant 1 persistence: LNK file written to user Startup folder by non-Explorer process [LLM] PlugX persistence — Run key 'G DATA' pointing to C:\Users\Public\GDatas\Avk.exe [LLM] MuddyViper persistence via ManageOnDriveUpdater scheduled task or Startup folder hijack [LLM] Zip Slip arbitrary file overwrite by archive-handling runtime (java/python) via path traversalArticles citing this technique (19)
crit The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications art-96