mitre-attack / car

Cyber Analytics Repository
Apache License 2.0
889 stars 300 forks source link

CAR-2021-11-002-T1547.004 #139

Closed Ptylu closed 2 years ago

Ptylu commented 2 years ago

-Finished- Detection of modification of registry key Notify,Userinit and Shell located in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ and HKEY_LOCAL_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon. When user logon, the Registry keys Notify, Userinit and Shell are used to load dedicated Windows component. Attacker may insert malicious payload following the legit value to launch a malicious payload.

Ptylu commented 2 years ago

-Completed-