From cybersec-toolkit
Detects MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs for suspicious auto-start entries, temp directory paths, encoded PowerShell, and LOLBin abuse.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersec-toolkit:hunting-for-registry-run-key-persistenceThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Registry Run keys (T1547.001) are one of the most commonly used persistence mechanisms by adversaries. When a program is added to a Run key in the Windows registry, it executes automatically when a user logs in. Attackers abuse keys under `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`, `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`, and their RunOnce counterparts to maintain persist...
Registry Run keys (T1547.001) are one of the most commonly used persistence mechanisms by adversaries. When a program is added to a Run key in the Windows registry, it executes automatically when a user logs in. Attackers abuse keys under HKLM\Software\Microsoft\Windows\CurrentVersion\Run, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and their RunOnce counterparts to maintain persistence. Sysmon Event ID 13 (RegistryEvent - Value Set) captures registry value modifications including the target object path, the process that made the change, and the new value. Detection involves monitoring these events for suspicious executables in temp directories, encoded PowerShell commands, LOLBin paths, and processes that do not normally create Run key entries. Chaining Event 13 with Event 1 (Process Creation) and Event 11 (FileCreate) strengthens detection by confirming payload creation and execution.
json, xml.etree.ElementTree, re modulesA JSON report listing suspicious Run key entries with the registry path, value written, modifying process, timestamp, MITRE technique mapping, severity rating, and recommended Sigma detection rules.
npx claudepluginhub 26zl/cybersec-toolkit --plugin cybersec-toolkitDetects MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs for suspicious auto-start entries, temp directory paths, encoded PowerShell, and LOLBin abuse.
Detects MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and chaining with process/file events to flag malicious auto-start entries.
Analyzes Sysmon Event ID 13 logs and registry queries to detect MITRE ATT&CK T1547.001 Run key persistence, identifying malicious Windows auto-start entries. Useful for threat hunting in Sysmon-enabled environments.