Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisHard
A security analyst is investigating an alert from an Endpoint Detection and Response (EDR) solution indicating 'Suspicious Registry Modification' on a Windows workstation. The alert specifically points to a change in the 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify' key. What does a malicious modification to this specific Registry key typically indicate?
- AEstablishment of persistence by injecting a malicious DLL into the logon process.
- BDisabling of Windows Defender Antivirus via Group Policy.
- CAttempted privilege escalation via a vulnerable service.
- DModification of the system's default password policy.
Show answer & explanationAnswer & explanation
Correct answer: A. Establishment of persistence by injecting a malicious DLL into the logon process.
The 'Winlogon\Notify' registry key is designed for legitimate programs to receive notifications about logon events. Malicious actors commonly abuse this key by registering a malicious DLL to be loaded and executed every time a user logs on, thereby achieving persistence and injecting code into a critical system process.
Why the other options are wrong
- B. Disabling Windows Defender is usually done through other Registry keys, Group Policy, or direct service manipulation, not via Winlogon Notify.
- C. Privilege escalation through vulnerable services usually involves exploiting service misconfigurations or vulnerabilities, not directly modifying Winlogon Notify.
- D. Password policies are typically managed through Group Policy or local security policies, not directly through the Winlogon Notify key.
Winlogon Notify Persistence
A Windows persistence technique where attackers register a malicious DLL under the Winlogon\Notify Registry key, causing it to be loaded and executed during the logon process.
- Abuses legitimate Winlogon functionality.
- Malicious DLLs loaded upon user logon.
- Provides high-privilege execution.
Memory trick: Registry keys help malware persist and notify Winlogon.