Skip to content

Hide Navigation Hide TOC

Sticky Key Like Backdoor Usage - Registry (baca5663-583c-45f9-b5dc-ea96a22ce542)

Detects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen

Cluster A Galaxy A Cluster B Galaxy B Level
Accessibility Features - T1546.008 (70e52b04-2a0c-4cea-9d18-7149f1df9dc5) Attack Pattern Sticky Key Like Backdoor Usage - Registry (baca5663-583c-45f9-b5dc-ea96a22ce542) Sigma-Rules 1
Accessibility Features - T1546.008 (70e52b04-2a0c-4cea-9d18-7149f1df9dc5) Attack Pattern Event Triggered Execution - T1546 (b6301b64-ef57-4cce-bb0b-77026f14a8db) Attack Pattern 2