Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisHard

A security analyst is investigating an alert from an Endpoint Detection and Response (EDR) solution indicating 'Suspicious Registry Modification' on a Windows workstation. The alert specifically points to a change in the 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify' key. What does a malicious modification to this specific Registry key typically indicate?

  1. AEstablishment of persistence by injecting a malicious DLL into the logon process.
  2. BDisabling of Windows Defender Antivirus via Group Policy.
  3. CAttempted privilege escalation via a vulnerable service.
  4. DModification of the system's default password policy.
Show answer & explanation

Correct answer: A. Establishment of persistence by injecting a malicious DLL into the logon process.

The 'Winlogon\Notify' registry key is designed for legitimate programs to receive notifications about logon events. Malicious actors commonly abuse this key by registering a malicious DLL to be loaded and executed every time a user logs on, thereby achieving persistence and injecting code into a critical system process.

Why the other options are wrong

  • B. Disabling Windows Defender is usually done through other Registry keys, Group Policy, or direct service manipulation, not via Winlogon Notify.
  • C. Privilege escalation through vulnerable services usually involves exploiting service misconfigurations or vulnerabilities, not directly modifying Winlogon Notify.
  • D. Password policies are typically managed through Group Policy or local security policies, not directly through the Winlogon Notify key.

Winlogon Notify Persistence

A Windows persistence technique where attackers register a malicious DLL under the Winlogon\Notify Registry key, causing it to be loaded and executed during the logon process.

  • Abuses legitimate Winlogon functionality.
  • Malicious DLLs loaded upon user logon.
  • Provides high-privilege execution.

Memory trick: Registry keys help malware persist and notify Winlogon.

More Host-Based Analysis questions