Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1547.001

T1547.001Registry Run Keys / Startup Folder

T1547.001 — Registry Run Keys / Startup Folder is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 34 detection use cases covering it and 19 threat-intel articles citing it.

PersistencePrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
34Use cases
19Articles
0Sub-techniques
2Tactics

Use cases covering this technique (34)

Registry Keys Used For Persistence ESCU actions · alerting P Windows Boot or Logon Autostart Execution In Startup Folder ESCU actions · hunting P Windows NorthStar C2 Agent Execution ESCU actions · alerting P Windows PowerShell MSIX Package Installation ESCU actions · alerting P Windows Registry BootExecute Modification ESCU actions · alerting P Windows Registry Modification for Safe Mode Persistence ESCU actions · alerting P [LLM] CoolClient persistence: 'goopdate' Run key and 'media_updaten' service creation Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure Bespoke exploit · hunting DSP [LLM] PATCHCORD 'BeaconBrowserHijack' Run-key persistence (APT36) Bespoke install · alerting DSΣPDDCS [LLM] SHEETCORD VBS Startup-folder persistence drop Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Co Bespoke exploit · hunting DSP Article-specific behavioural hunt — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware deliver Bespoke exploit · hunting DSP [LLM] CornFlake RAT persistence via svchost32.exe masquerade in %APPDATA% Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially Bespoke exploit · hunting DSP [LLM] axios RAT persistence: HKCU Run value MicrosoftUpdate pointing to system.bat Bespoke install · alerting DSΣPDDCS [LLM] Gamaredon WinRAR CVE-2025-8088 ADS path-traversal dropping HTA/VBS into Startup folder Bespoke install · alerting DSΣPDDCS [LLM] Gamaredon HTA downloader auto-executing from Startup folder at logon (mshta.exe) Bespoke exploit · alerting DSΣPDDCS [LLM] easy-day-js Windows persistence: Run key 'NvmProtocal' / protocal.cjs autostart Bespoke install · alerting DSΣPDDCS [LLM] easy-day-js implant artifacts dropped: protocal.cjs / NodePackages / cross-OS persistence files Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — ESET takes part in Operation Endgame to disrupt Amadey and Stealc Bespoke exploit · hunting DSP Article-specific behavioural hunt — ESET takes part in Operation Endgame to disrupt Amadey and Stealc Bespoke exploit · hunting DSP [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Webworm: New burrowing techniques Bespoke exploit · hunting DSP Article-specific behavioural hunt — Webworm: New burrowing techniques Bespoke exploit · hunting DSP Article-specific behavioural hunt — FrostyNeighbor: Fresh mischief and digital shenanigans Bespoke exploit · hunting DSP Article-specific behavioural hunt — FrostyNeighbor: Fresh mischief and digital shenanigans Bespoke exploit · hunting DSP [LLM] IoliteLabs Stage-2 regsvr32 LOLbin loading ntuser DLL from fake Chrome\ChromeUpdate path Bespoke install · alerting DSΣPDD Article-specific behavioural hunt — TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package Bespoke exploit · hunting DSP [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) Bespoke install · alerting DSΣPDDCS [LLM] ValleyRAT registry-resident shellcode (HKCU\Console\0|1) and MyPythonApp Run-key persistence Bespoke install · hunting DSΣP [LLM] DRILLAPP variant 1 persistence: LNK file written to user Startup folder by non-Explorer process Bespoke install · alerting DSΣPDDCS [LLM] PlugX persistence — Run key 'G DATA' pointing to C:\Users\Public\GDatas\Avk.exe Bespoke install · alerting DSΣPDD [LLM] MuddyViper persistence via ManageOnDriveUpdater scheduled task or Startup folder hijack Bespoke install · alerting DSPDDCS [LLM] Zip Slip arbitrary file overwrite by archive-handling runtime (java/python) via path traversal Bespoke exploit · hunting DSΣPDDCS

Articles citing this technique (19)