Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / DFI / ARTEFACT / WINDOWS / REGISTRY / RegRipper

Persistence & Autoruns

PluginHiveWhat it gives
runSOFTWARE / NTUSERRun keys
runonceexSOFTWARERunOnceEx
cmdprocNTUSERcmd autorun
appinitdllsSOFTWAREDLL injection
appcertdllsSYSTEMAppCert DLL persistence
imagefileSOFTWAREIFEO hijacks
svcdllSYSTEMService DLLs
servicesSYSTEMServices
taskcacheSOFTWAREScheduled tasks
tasksSOFTWARETask definitions
scriptleturlSOFTWARE / USRCLASSCOM hijack
inprocserverSOFTWARECLSID DLL hijack
shelloverlaySOFTWAREShell overlay hijack
winlogon_tlnSOFTWAREWinlogon persistence