Detailedlikelihood: Mediumseverity: MediumStable
CAPEC-270Modification of Registry Run Keys
Abstraction
Detailed
Status
Stable
Likelihood
Medium
Severity
Medium
Description
An adversary adds a new entry to the "run keys" in the Windows registry so that an application of their choosing is executed when a user logs in. In this way, the adversary can get their executable to operate and run on the target system with the authorized user's level of permissions. This attack is a good way for an adversary to run persistent spyware on a user's machine, such as a keylogger.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 2
Related attack patterns· 5
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | External Control of System or Configuration Settingcwe-15 | 100% | live |
Related to2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Registry Run Keys / Startup Foldert1547.001 | 100% | live |
| SubTechnique | Active Setupt1547.014 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.