logo

Who Left the Backdoor Open? Using Startupinfo for the Win

ID: b398b71c-5865-53bb-ac61-d0c2fa5014f7

STIX ID: report--b398b71c-5865-53bb-ac61-d0c2fa5014f7

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

**Executive summary:** This blog post demonstrates that the Windows startupinfo.xml artifact (C:\Windows\System32\WDI\LogFiles\StartupInfo) records the first 90 seconds of user logon process activity and can reveal useful IoCs—such as user SID, parent/child PIDs, command lines, timestamps, and resource usage—enabling detection of registry-based PowerShell Empire persistence, while noting that WMI-based persistence can execute outside that 90-second window and evade this specific artifact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.