
Rule Info
Name
Suspicious NT Windows Autorun Key Modification
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious NT Autorun Keys Modification patterns are not commonly used or modified by legitimate programs.
This could be an indication of an adversary's attempt to persist in a stealthy manner.
Date
2025-04-23 00:00:00
Modified
None
Id
f186e9a8-16fe-447f-9e0d-47b40d403053
Tags
attack.persistence attack.t1547.001
Type
Nextron Sigma feed only (private)