Unusual process modified registry run key
Identifies an attempt by unusual Windows native processes to modify the run key and gain persistence on users logons or machine reboots.
- Platform: Windows
- Severity: High
- MITRE Tactic: Persistence
- MITRE Techniques: T1547, T1547.001