Suspicious Command Processor AutoRun Persistence via Registry Set

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-05-14
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects writes to the Command Processor AutoRun registry value, which forces a command to run whenever cmd.exe starts and was used for persistence in the Uncorking Old Wine Cobalt Strike loader. This value is rarely set by legitimate software and is a well-known event-triggered execution vector.

Related detections9 linkedT1546 — drag to rearrange
Malicious IFEO Debugger Hijack of vds.exe by FishMonger
AdminSDHolder Permissions Changed for Persistence (via security)
Suspicious Image File Execution Options Debugger Hijack by Miner Campaign
Suspicious Persistence via Shell Script Dropped in profile.d Directory (via file_event)
Suspicious Python Site Hook or PTH File Written to Site-Packages via File Event
Suspicious MOTD Or Git Hook Script Creation For Linux Persistence
Windows: Suspicious Outlook VbaProject.OTM Macro File Created
Windows MSSQL: Extended Stored Procedure execution with provider name MSSQLSERVER and message containing 'maggie'
Windows Registry App Paths Default Property Change Using Suspicious Values
Suspicious Command Processor AutoRun Persistence via Registry Set
Pivot detection · T1546 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.