Skip to content
Invoke-IR edited this page Oct 18, 2014 · 1 revision

Table of Contents


Persistence Mechanisms

SERVICE_CREATION

SERVICE_DELETION

SCHEDULEDJOB_CREATION

SCHEDULEDJOB_DELETION

STARTUPCOMMAND_CREATION

  • Monitors the Win32_StartupCommand for __InstanceCreationEvents.
  • Locations Monitored:
    • HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    • HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
    • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    • HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
    • HKU\ProgID\Software\Microsoft\Windows\CurrentVersion\Run
    • systemdrive\Documents and Settings\All Users\Start Menu\Programs\Startup
    • systemdrive\Documents and Settings\username\Start Menu\Programs\Startup

STARTUPCOMMAND_DELETION


Network Resource

SHARE_CREATION

  • Monitors the Win32_Share for __InstanceCreationEvents.

SHARE_DELETION

  • Monitors the Win32_Share for __InstanceDeletionEvents.

NETWORKCONNECTION_CREATION

NETWORKCONNECTION_DELETION

SERVERCONNECTION_CREATION

SERVERCONNECTION_DELETION


Rootkit

DRIVER_CREATION

DRIVER_DELETION