logo

Hiding Registry keys with PSReflect

ID: 2203da05-6236-5156-a04e-a9ca106ae7e2

STIX ID: report--2203da05-6236-5156-a04e-a9ca106ae7e2

Feed Name: SpecterOps Blog

Threat Score
30/100

Date Published: 2017-07-14

Date Updated: 2026-04-30

Author: Brian Reitz

...
...

This technical write-up demonstrates how Kovter/Poweliks-style fileless persistence can be implemented by placing mshta/javascript payloads in registry Run values whose names begin with a null character, which prevents standard Win32 tools (like Regedit) from enumerating them; the author provides a PowerShell PSReflect proof-of-concept that calls native ntdll functions (NtOpenKey/NtSetValueKey/NtClose) to create such hidden values and discusses detection and mitigation implications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.