Rules Contributing to Suspicious Windows Registry Event: Persistence Alert

The following rules are used to identify suspicious Windows registry events usually in the persistence stage. Any one or more of these will trigger the Suspicious Windows Registry Event: Persistence Alert. Details for each rule can be viewed by clicking the More Details link in the description.

Title

Description

Potential Persistence Via Microsoft office Add-in

Detect potential persistence via the creation of a Microsoft office add-in file to make it run automatically.