%GoCortexIO Snippets

Cortex XDR

Spot persistence attempts by monitoring reg.exe command-line executions adding auto-start entries under Windows Run or RunOnce registry keys.

| 5 minutes to implement | ~1 min read
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.

# Snippet | Run key persistence written via reg.exe.

## Scenario 

An attacker establishing user-mode persistence by writing a value under the `Run` or `RunOnce` registry keys with `reg.exe add`. Trivial to deploy, trivial to spot if you are looking.

- [https://attack.mitre.org/techniques/T1547/001/](https://attack.mitre.org/techniques/T1547/001/)
- [https://learn.microsoft.com/en-us/windows/win32/setupapi/run-and-runonce-registry-keys](https://learn.microsoft.com/en-us/windows/win32/setupapi/run-and-runonce-registry-keys)

`Logic:` spotted via the literal Run/RunOnce key path on the command line.

For full coverage pair this with a registry-event hunt; this snippet is the quick check that does not require deeper telemetry plumbing.

- [https://xsoar.pan.dev/docs/reference/playbooks/mitre-attck-co-a---t1547001---registry-run-keys-startup-folder](https://xsoar.pan.dev/docs/reference/playbooks/mitre-attck-co-a---t1547001---registry-run-keys-startup-folder)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
dataset = xdr_data
| filter event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START
| filter lowercase(action_process_image_name) = "reg.exe"
| filter lowercase(action_process_image_command_line) contains " add "
| filter lowercase(action_process_image_command_line) contains "\\currentversion\\run"
    or lowercase(action_process_image_command_line) contains "\\currentversion\\runonce"
| fields _time, agent_hostname, actor_effective_username,
    causality_actor_process_image_name, action_process_image_command_line
| limit 200
See all 21 snippets