Hunting For Registry Run Key Persistence

Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.

26zl Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/hunting-for-registry-run-key-persistence commit b82ead5a78

Frequently asked questions

npx skillmds@latest add 26zl/hunting-for-registry-run-key-persistence