From asi
Detects MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and chaining with process/file events to flag malicious auto-start entries.
npx claudepluginhub plurigrid/asi --plugin asiThis skill uses the workspace's default tool permissions.
Registry Run keys (T1547.001) are one of the most commonly used persistence mechanisms by adversaries. When a program is added to a Run key in the Windows registry, it executes automatically when a user logs in. Attackers abuse keys under `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`, `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`, and their RunOnce counterparts to maintain persist...
Detects MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs to identify suspicious auto-start entries like temp paths and LOLBins.
Analyzes Sysmon Event ID 13 logs and registry queries to detect MITRE ATT&CK T1547.001 Run key persistence, identifying malicious Windows auto-start entries. Useful for threat hunting in Sysmon-enabled environments.
Hunt for Windows registry persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking. For threat hunting, IR, and security assessments.
Share bugs, ideas, or general feedback.
Registry Run keys (T1547.001) are one of the most commonly used persistence mechanisms by adversaries. When a program is added to a Run key in the Windows registry, it executes automatically when a user logs in. Attackers abuse keys under HKLM\Software\Microsoft\Windows\CurrentVersion\Run, HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and their RunOnce counterparts to maintain persistence. Sysmon Event ID 13 (RegistryEvent - Value Set) captures registry value modifications including the target object path, the process that made the change, and the new value. Detection involves monitoring these events for suspicious executables in temp directories, encoded PowerShell commands, LOLBin paths, and processes that do not normally create Run key entries. Chaining Event 13 with Event 1 (Process Creation) and Event 11 (FileCreate) strengthens detection by confirming payload creation and execution.
json, xml.etree.ElementTree, re modulesA JSON report listing suspicious Run key entries with the registry path, value written, modifying process, timestamp, MITRE technique mapping, severity rating, and recommended Sigma detection rules.