Suspicious persistence via registry modification

Adversaries may abuse the registry to achieve persistence by modifying the keys that are unlikely modified by legitimate processes.

Back to all rules