persistence/startup-folder

write file to startup folder

rule:
  meta:
    name: write file to startup folder
    namespace: persistence/startup-folder
    authors:
      - matthew.williams@mandiant.com
    scopes:
      static: function
      dynamic: thread
    att&ck:
      - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001]
    examples:
      - 07F7846BBCDA782E5639292AD93907EB:0x401040
  features:
    - and:
      - match: get startup folder
      - or:
        - match: copy file
        - match: move file
        - match: host-interaction/file-system/write

last edited: 2023-11-24 10:34:28