Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.
All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.
cybersecurity
threat-hunting
persistence
registry-run-keys
t1547-001
sysmon
threat-hunting
windows-forensics
mitre-attack
1.0
mahipal
Apache-2.0
Executable Denylisting
Execution Isolation
File Metadata Consistency Validation
Content Format Conversion
File Content Analysis
DE.CM-01
DE.AE-02
DE.AE-07
ID.RA-05
Hunting for Registry Run Key Persistence
Overview
Registry Run keys (T1547.001) are one of the most commonly used persistence mechanisms by adversaries. When a program is added to a Run key in the Windows registry, it executes automatically when a user logs in. Attackers abuse keys under HKLM\Software\Microsoft\Windows\CurrentVersion\Run, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and their RunOnce counterparts to maintain persistence. Sysmon Event ID 13 (RegistryEvent - Value Set) captures registry value modifications including the target object path, the process that made the change, and the new value. Detection involves monitoring these events for suspicious executables in temp directories, encoded PowerShell commands, LOLBin paths, and processes that do not normally create Run key entries. Chaining Event 13 with Event 1 (Process Creation) and Event 11 (FileCreate) strengthens detection by confirming payload creation and execution.
When to Use
When investigating security incidents that require hunting for registry run key persistence
When building detection rules or threat hunting queries for this domain
When SOC analysts need structured procedures for this analysis type
When validating security monitoring coverage for related attack techniques
Prerequisites
Windows systems with Sysmon installed and configured to log Event ID 13
Sysmon config with RegistryEvent rules for Run/RunOnce keys
Python 3.9+ with json, xml.etree.ElementTree, re modules
SIEM or log aggregator collecting Sysmon logs (Splunk, Elastic, Sentinel)
Knowledge of legitimate auto-start programs for baseline comparison
Steps
Collect Sysmon Event ID 13 logs filtered for Run/RunOnce key paths
Compare against known-good baseline of legitimate auto-start entries
Check if the modifying process (Image) is unusual (cmd.exe, powershell.exe, python.exe)
Chain with Event ID 1 to verify if the registered binary was recently created
Generate detection report with MITRE ATT&CK mapping and severity scores
Produce Sigma/Splunk detection rules from findings
Expected Output
A JSON report listing suspicious Run key entries with the registry path, value written, modifying process, timestamp, MITRE technique mapping, severity rating, and recommended Sigma detection rules.