LoFP LoFP / legitimate addition of logon scripts via the command line by administrators or third party tools

Techniques

Sample rules

Potential Persistence Via Logon Scripts - CommandLine

Description

Detects the addition of a new LogonScript to the registry value “UserInitMprLogonScript” for potential persistence

Detection logic

condition: selection
selection:
  CommandLine|contains: UserInitMprLogonScript