• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Persistence via 'Canon Configuration Reader'/'Stardock DeElevation Tool' Run key

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 7 days ago•0•0•0

    Detects the creation of Windows Registry Run keys with names mimicking known applications (e.g., 'Canon Configuration Reader' or 'Stardock DeElevation Tool'). These naming patterns are highly suspicious and indicative of attempts to achieve persistence or perform defense evasion via registry-based autostart execution.

    Sigma

    Tags

    T1547.001 - Registry Run Keys / Startup FolderT1036.005 - Match Legitimate Resource Name or LocationTA0003 - PersistenceTA0005 - StealthRegistry Key CreateRegistry Value SetWindowsWindows Sysmonattack.persistenceattack.privilege_escalationattack.defense_evasionattack.t1547.001attack.t1053.005attack.t1036.005

    Found in

    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 6 days ago
    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 8 days ago
    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 8 days ago
    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 8 days ago
    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 8 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?