Hiding Registry keys with PSReflect
ID: 2203da05-6236-5156-a04e-a9ca106ae7e2
STIX ID: report--2203da05-6236-5156-a04e-a9ca106ae7e2
Feed Name: SpecterOps Blog
This technical write-up demonstrates how Kovter/Poweliks-style fileless persistence can be implemented by placing mshta/javascript payloads in registry Run values whose names begin with a null character, which prevents standard Win32 tools (like Regedit) from enumerating them; the author provides a PowerShell PSReflect proof-of-concept that calls native ntdll functions (NtOpenKey/NtSetValueKey/NtClose) to create such hidden values and discusses detection and mitigation implications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
