Skip to content

Instantly share code, notes, and snippets.

@hasherezade
Last active December 31, 2023 19:26
Show Gist options
  • Save hasherezade/e3b5682fee27500c5dabf5343f447de3 to your computer and use it in GitHub Desktop.
Save hasherezade/e3b5682fee27500c5dabf5343f447de3 to your computer and use it in GitHub Desktop.
Demo: persistence key not visible for sysinternals autoruns (in a default configuration - read more: https://twitter.com/hasherezade/status/849756054145699840)
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
@="Rundll32.exe SHELL32.DLL,ShellExec_RunDLL \"C:\\ProgramData\\test.exe\""
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment