Registry Run Keys
Course Content
Once adversaries have taken advantage of the Registry Run Keys technique, they can take a look around and elevate their privileges to gain more access and achieve persistence. Threat actors like FIN10 have been known to establish persistence by using the Registry option in PowerShell Empire to add a Run key.
It’s important to mitigate this activity and block potentially malicious software that may be executed through run key or upon startup.
Get the hands-on skills you need to detect and mitigate this type of attack in Cybrary's MITRE ATT&CK Framework courses aligned to the tactics and techniques used by the financially motivated threat group FIN10. Prevent adversaries from accomplishing the tactic of Persistence in your environment today.
What will I be able to accomplish after taking these courses?
What are the prerequisites for these courses?