Windows PrivEsc : Autorun
Tags
attack-pattern: | Malicious File - T1204.002 Powershell - T1059.001 Python - T1059.006 Server - T1583.004 Server - T1584.004 Software - T1592.002 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | 53f0171d-c14d-499b-9387-630149bdaa95 |
Fingerprint | bf33981815af27a5 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | April 13, 2023, 3:24 p.m. |
Added to db | April 13, 2023, 5:45 p.m. |
Last updated | Nov. 17, 2024, 12:58 a.m. |
Headline | Windows PrivEsc : Autorun |
Title | Windows PrivEsc : Autorun |
Detected Hints/Tags/Attributes | 26/1/11 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 167 | ✔ | Cybersecurity on Medium | https://medium.com/feed/tag/cybersecurity | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | File | 30 | autoruns.exe |
|
Details | File | 10 | autorun.exe |
|
Details | File | 4 | autoruns64.exe |
|
Details | File | 14 | powerup.ps1 |
|
Details | File | 41 | system.obj |
|
Details | File | 1 | startupprogram.exe |
|
Details | File | 1 | accesschk64.exe |
|
Details | File | 2 | c:\program files\autorun program\program.exe |
|
Details | File | 28 | program.exe |
|
Details | Windows Registry Key | 493 | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run |
|
Details | Windows Registry Key | 470 | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce |