hunting-for-registry-persistence-mechanisms skill (Anthropic-Cybersecurity-Skills)
- Install
- SKILL.md (verbatim)
- When to Use
- Prerequisites
- Workflow
- Key Concepts
- Tools & Systems
- Common Scenarios
- Output Format
- Other files in this skill
- assets/template.md (verbatim)
- Hunt Metadata
- Hypothesis
- Target Techniques
- Data Sources
- Queries Executed
- Query 1: [Description]
- Query 2: [Description]
- Findings
- IOCs Discovered
- Network IOCs
- Host IOCs
- Hunt Results Summary
- Hypothesis Outcome
- Recommendations
- Analyst Notes
- references/api-reference.md (verbatim)
- Libraries Used
- CLI Interface
- Core Functions
- scanpersistencekeys(categories=None)
- comparebaseline(baselinefile, currentscan=None)
- Registry Categories Scanned
- Dependencies
- references/standards.md (verbatim)
- MITRE ATT&CK Mappings
- Detection Data Sources
- References
- references/workflows.md (verbatim)
- Phase 1: Data Collection and Querying
- Splunk SPL Query
- KQL Query (Microsoft Defender for Endpoint)
- Phase 2: Baseline and Anomaly Detection
- Step 2.1 - Establish Normal Behavior Baseline
- Step 2.2 - Identify Anomalies
- Phase 3: Investigation and Correlation
- Step 3.1 - Deep Dive Analysis
- Step 3.2 - Attack Chain Reconstruction
- Phase 4: Validation and Response
- Step 4.1 - True/False Positive Determination
- Step 4.2 - Response Actions
- Phase 5: Documentation and Reporting
- Step 5.1 - Hunt Report
- Step 5.2 - Knowledge Base Update
What it does. Hunts for registry-based persistence mechanisms (MITRE T1547) in Windows Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/hunting-for-registry-persistence-mechanisms/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill hunting-for-registry-persistence-mechanisms, or copy the skill folder into~/.claude/skills/hunting-for-registry-persistence-mechanisms/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/hunting-for-registry-persistence-mechanisms/SKILL.md
SKILL.md (verbatim)
name: hunting-for-registry-persistence-mechanisms
description: Hunts for registry-based persistence mechanisms (MITRE T1547) in Windows
environments, including Run/RunOnce keys, Winlogon Shell/Userinit modifications, Image
File Execution Options (IFEO) debugger injection, and COM hijacking via CLSID overrides.
Use when auditing the registry for persistence artifacts or building detections for
registry-based malware autostart techniques.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- mitre-attack
- registry
- persistence
- windows
- t1547
- proactive-detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Executable Denylisting
- Execution Isolation
- File Metadata Consistency Validation
- Content Format Conversion
- File Content Analysis
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1046
- T1057
- T1082
- T1083
- T1547
Hunting For Registry Persistence Mechanisms
When to Use
- When proactively hunting for indicators of hunting for registry persistence mechanisms in the environment
- After threat intelligence indicates active campaigns using these techniques
- During incident response to scope compromise related to these techniques
- When EDR or SIEM alerts trigger on related indicators
- During periodic security assessments and purple team exercises
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
- Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
- Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
- Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
- Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
- Validate Findings: Distinguish true positives from false positives through contextual analysis.
- Correlate Activity: Link findings to broader attack chains and threat actor TTPs.
- Document and Report: Record findings, update detection rules, and recommend response actions.
Key Concepts
| Concept | Description |
|---|---|
| T1547.001 | Registry Run Keys |
| T1547.004 | Winlogon Helper DLL |
| T1546.012 | IFEO Injection |
| T1546.015 | COM Hijacking |
Tools & Systems
| Tool | Purpose |
|---|---|
| CrowdStrike Falcon | EDR telemetry and threat detection |
| Microsoft Defender for Endpoint | Advanced hunting with KQL |
| Splunk Enterprise | SIEM log analysis with SPL queries |
| Elastic Security | Detection rules and investigation timeline |
| Sysmon | Detailed Windows event monitoring |
| Velociraptor | Endpoint artifact collection and hunting |
| Sigma Rules | Cross-platform detection rule format |
Common Scenarios
- Scenario 1: Malware adding HKCU Run key for user-level persistence
- Scenario 2: Adversary modifying Winlogon Shell for system-level persistence
- Scenario 3: IFEO debugger injection for accessibility feature backdoor
- Scenario 4: COM object InprocServer32 hijack for DLL loading
Output Format
Hunt ID: TH-HUNTIN-[DATE]-[SEQ]
Technique: T1547.001
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]
Other files in this skill
- LICENSE
- assets/template.md
- references/api-reference.md
- references/standards.md
- references/workflows.md
- scripts/agent.py
- scripts/process.py
assets/template.md (verbatim)
Hunting For Registry Persistence Mechanisms - Hunt Template
Hunt Metadata
| Field | Value |
|---|---|
| Hunt ID | TH-HUNTIN-YYYY-MM-DD-NNN |
| Analyst | |
| Date Started | |
| Date Completed | |
| Status | [ ] In Progress / [ ] Complete |
| Priority | [ ] Critical / [ ] High / [ ] Medium / [ ] Low |
Hypothesis
Statement: [Formulate a clear, testable hypothesis]
Basis: [ ] Threat Intel / [ ] ATT&CK Gap / [ ] Anomaly / [ ] Incident Follow-up
Target Techniques
- T1547.001 - Registry Run Keys
- T1547.004 - Winlogon Helper DLL
- T1546.012 - IFEO Injection
- T1546.015 - COM Hijacking
Data Sources
- Sysmon Event Logs
- Windows Security Event Logs
- EDR Telemetry (Platform: _____________)
- SIEM (Platform: _____________)
- Network Logs (Proxy/Firewall/DNS)
- Cloud Audit Logs
- Email Gateway Logs
- Application Logs
Queries Executed
Query 1: [Description]
[Query text]
Results: [Count] events | Execution Time: [Duration]
Query 2: [Description]
[Query text]
Results: [Count] events | Execution Time: [Duration]
Findings
| # | Timestamp | Host | User | Technique | Evidence Summary | Risk | Verdict |
|---|---|---|---|---|---|---|---|
| 1 | TP / FP / BTP | ||||||
| 2 | TP / FP / BTP | ||||||
| 3 | TP / FP / BTP |
IOCs Discovered
Network IOCs
| Type | Value | Context | Confidence |
|---|---|---|---|
| IP | |||
| Domain | |||
| URL |
Host IOCs
| Type | Value | Context | Confidence |
|---|---|---|---|
| SHA256 | |||
| Filename | |||
| Registry Key | |||
| Scheduled Task |
Hunt Results Summary
| Metric | Count |
|---|---|
| Total Events Analyzed | |
| Anomalies Identified | |
| True Positives | |
| False Positives | |
| Benign True Positives | |
| New IOCs Discovered | |
| Detection Rules Created | |
| Detection Rules Updated |
Hypothesis Outcome
- Confirmed: Evidence supports the hypothesis
- Partially Confirmed: Some evidence found, further investigation needed
- Refuted: No evidence found
- Inconclusive: Insufficient data
Recommendations
- Immediate Actions: [Containment, remediation steps]
- Detection Improvements: [New rules, tuning recommendations]
- Visibility Gaps: [Missing data sources, coverage needs]
- Security Hardening: [Configuration changes, policy updates]
- Follow-up Hunts: [Related hypotheses to investigate]
Analyst Notes
[Free-form notes, observations, and lessons learned]
references/api-reference.md (verbatim)
API Reference — Hunting for Registry Persistence Mechanisms
Libraries Used
- subprocess: Execute
reg query /sto enumerate registry persistence keys - re: Pattern matching for suspicious values in registry entries
- json: Baseline file I/O and structured output
CLI Interface
python agent.py scan [--categories run_keys winlogon ifeo] [--save-baseline out.json]
python agent.py compare --baseline baseline.json
Core Functions
scan_persistence_keys(categories=None)
Enumerates registry persistence keys across 8 categories and flags suspicious entries.
Parameters:
| Name | Type | Description |
|---|---|---|
categories |
list | Optional subset of categories to scan (default: all 8) |
Returns: dict with categories map, all_suspicious list, and total_suspicious count.
compare_baseline(baseline_file, current_scan=None)
Compares current registry state against a saved baseline to detect new persistence entries.
Parameters:
| Name | Type | Description |
|---|---|---|
baseline_file |
str | Path to baseline JSON file from previous scan |
Returns: dict with baseline_entries count, new_entries count, and findings list.
Registry Categories Scanned
| Category | Keys | MITRE Technique |
|---|---|---|
run_keys |
Run, RunOnce, RunOnceEx | T1547.001 |
winlogon |
Winlogon Shell, Userinit | T1547.004 |
ifeo |
Image File Execution Options | T1546.012 |
appinit |
AppInit_DLLs | T1546.010 |
shell_extensions |
ShellExecuteHooks | T1546.015 |
browser_helpers |
Browser Helper Objects | T1176 |
com_hijack |
CLSID overrides in HKCU | T1546.015 |
boot_execute |
BootExecute, Session Manager | T1542.003 |
Dependencies
No external packages required — uses Python standard library and reg.exe.
references/standards.md (verbatim)
Standards and References - Hunting For Registry Persistence Mechanisms
MITRE ATT&CK Mappings
| Technique | Name | Description |
|---|---|---|
| T1547.001 | Registry Run Keys | See attack.mitre.org/techniques/T1547/001 |
| T1547.004 | Winlogon Helper DLL | See attack.mitre.org/techniques/T1547/004 |
| T1546.012 | IFEO Injection | See attack.mitre.org/techniques/T1546/012 |
| T1546.015 | COM Hijacking | See attack.mitre.org/techniques/T1546/015 |
Detection Data Sources
| Source | Event ID | Purpose |
|---|---|---|
| Sysmon | 1 | Process creation with command line |
| Sysmon | 3 | Network connection initiated |
| Sysmon | 7 | Image loaded (DLL) |
| Sysmon | 10 | Process access (LSASS) |
| Sysmon | 11 | File creation |
| Sysmon | 12/13 | Registry create/set |
| Sysmon | 22 | DNS query |
| Sysmon | 25 | Process tampering |
| Windows Security | 4624 | Successful logon |
| Windows Security | 4625 | Failed logon |
| Windows Security | 4648 | Explicit credential logon |
| Windows Security | 4672 | Special privileges assigned |
| Windows Security | 4688 | Process creation |
| Windows Security | 4697 | Service installed |
| Windows Security | 4698 | Scheduled task created |
| Windows Security | 4769 | Kerberos TGS requested |
| Windows Security | 5140 | Network share accessed |
References
- MITRE ATT&CK Framework: https://attack.mitre.org/
- Sigma Detection Rules: https://github.com/SigmaHQ/sigma
- LOLBAS Project: https://lolbas-project.github.io/
- Atomic Red Team Tests: https://github.com/redcanaryco/atomic-red-team
- Red Canary Threat Detection Report
- SANS Threat Hunting Summit Resources
references/workflows.md (verbatim)
Detailed Hunting Workflow - Hunting For Registry Persistence Mechanisms
Phase 1: Data Collection and Querying
Splunk SPL Query
index=sysmon (EventCode=12 OR EventCode=13)
| where match(TargetObject, "(?i)\\\\CurrentVersion\\\\(Run|RunOnce|Policies\\\\Explorer\\\\Run)")
| table _time Computer User EventType TargetObject Details Image
KQL Query (Microsoft Defender for Endpoint)
DeviceRegistryEvents
| where RegistryKey has_any ("CurrentVersion\\Run","Winlogon\\Shell","Image File Execution Options")
| where ActionType in ("RegistryValueSet","RegistryKeyCreated")
| project Timestamp, DeviceName, RegistryKey, RegistryValueName, RegistryValueData
Phase 2: Baseline and Anomaly Detection
Step 2.1 - Establish Normal Behavior Baseline
- Collect 30 days of historical data for the targeted technique
- Document expected patterns, frequencies, and legitimate use cases
- Identify known false positive sources and document exceptions
- Build statistical baseline (mean, standard deviation) for key metrics
Step 2.2 - Identify Anomalies
- Compare current activity against the 30-day baseline
- Flag events exceeding 3 standard deviations from normal
- Prioritize anomalies by risk score and potential business impact
- Cross-reference with threat intelligence for known IOCs
Phase 3: Investigation and Correlation
Step 3.1 - Deep Dive Analysis
- For each anomaly, collect full process tree context
- Correlate with network activity, file operations, and authentication events
- Check binary signatures, file hashes, and certificate validity
- Review user account context and access patterns
Step 3.2 - Attack Chain Reconstruction
- Map findings to MITRE ATT&CK kill chain stages
- Identify initial access vector if applicable
- Trace lateral movement and privilege escalation paths
- Determine data access and potential exfiltration
Phase 4: Validation and Response
Step 4.1 - True/False Positive Determination
- Verify findings with system owners and IT operations
- Check change management records for authorized activities
- Validate user context (authorized actions vs. compromised account)
- Document determination rationale for each finding
Step 4.2 - Response Actions
- For confirmed threats: initiate incident response procedures
- For detection gaps: create or update detection rules
- For false positives: tune existing rules and update exclusions
- Update threat hunting playbook with lessons learned
Phase 5: Documentation and Reporting
Step 5.1 - Hunt Report
- Summarize hypothesis, methodology, and findings
- Include all queries executed and their results
- Document IOCs discovered and detection rules created
- Provide recommendations for security improvements
Step 5.2 - Knowledge Base Update
- Add findings to threat intelligence platform
- Update MITRE ATT&CK coverage heatmap
- Share detection rules via Sigma format
- Schedule follow-up hunts for related techniques
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.