Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium
A security analyst is conducting a malware analysis of a suspicious executable found on a Windows endpoint. The goal is to determine if the malware attempts to establish persistence by modifying the Windows Registry. Which specific registry key path is a common target for malware to ensure execution upon system startup for the currently logged-on user?
- AHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- BHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
- CHKEY_CLASSES_ROOT\exefile\shell\open\command
- DHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Show answer & explanationAnswer & explanation
Correct answer: D. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The `HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run` registry key is a common persistence mechanism that allows programs to execute automatically whenever the current user logs on. This key specifically impacts the current user, making it a frequent target for malware aiming for user-level persistence.
Why the other options are wrong
- A. This key (HKLM) ensures execution for *all* users upon system startup, which is also common but HKCU is specifically for the *currently logged-on user* as per the question.
- B. This path stores information about Windows services, which is another persistence method, but the question specifically asks about execution upon system startup for the *currently logged-on user* via a 'Run' key type of mechanism.
- C. This path relates to file association (how `.exe` files are opened) and is less commonly used for direct startup persistence than the `Run` keys.
Windows Run Keys
Registry keys (`...\CurrentVersion\Run` and `...\CurrentVersion\RunOnce`) that Windows checks during startup or user logon to automatically execute specified programs.
- Common malware persistence mechanism.
- HKLM affects all users, HKCU affects the current user.
- `RunOnce` keys execute only once and are then deleted.
Memory trick: To auto-run, malware goes to the 'Run' keys, either for 'all' or just the 'current' user.