Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium

A security analyst is conducting a malware analysis of a suspicious executable found on a Windows endpoint. The goal is to determine if the malware attempts to establish persistence by modifying the Windows Registry. Which specific registry key path is a common target for malware to ensure execution upon system startup for the currently logged-on user?

  1. AHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  2. BHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
  3. CHKEY_CLASSES_ROOT\exefile\shell\open\command
  4. DHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Show answer & explanation

Correct answer: D. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

The `HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run` registry key is a common persistence mechanism that allows programs to execute automatically whenever the current user logs on. This key specifically impacts the current user, making it a frequent target for malware aiming for user-level persistence.

Why the other options are wrong

  • A. This key (HKLM) ensures execution for *all* users upon system startup, which is also common but HKCU is specifically for the *currently logged-on user* as per the question.
  • B. This path stores information about Windows services, which is another persistence method, but the question specifically asks about execution upon system startup for the *currently logged-on user* via a 'Run' key type of mechanism.
  • C. This path relates to file association (how `.exe` files are opened) and is less commonly used for direct startup persistence than the `Run` keys.

Windows Run Keys

Registry keys (`...\CurrentVersion\Run` and `...\CurrentVersion\RunOnce`) that Windows checks during startup or user logon to automatically execute specified programs.

  • Common malware persistence mechanism.
  • HKLM affects all users, HKCU affects the current user.
  • `RunOnce` keys execute only once and are then deleted.

Memory trick: To auto-run, malware goes to the 'Run' keys, either for 'all' or just the 'current' user.

More Host-Based Analysis questions