• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    REVSTEALER Modules Registry Run Key Persistence

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated Sep 6, 2026•0•0•2

    This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.

    Microsoft Sentinel (KQL)

    Tags

    T1547.001 - Registry Run Keys / Startup FolderTA0003 - PersistenceRegistry Value SetWindowsWindows Defender Atpkql

    Found in

    • REVSTEALER Infostealer Ramps Up With Follow-on ModulesLast updated Sep 7, 2026
    • REVSTEALER: Sophisticated Infostealer with Polygon C2 ResilienceLast updated Sep 6, 2026
    • REVSTEALER: Sophisticated Infostealer with Polygon C2 ResilienceLast updated Sep 6, 2026
    • REVSTEALER: Sophisticated Infostealer with Polygon C2 ResilienceLast updated Sep 6, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?