Who Left the Backdoor Open? Using Startupinfo for the Win
ID: b398b71c-5865-53bb-ac61-d0c2fa5014f7
STIX ID: report--b398b71c-5865-53bb-ac61-d0c2fa5014f7
Feed Name: TrustedSec blog
**Executive summary:** This blog post demonstrates that the Windows startupinfo.xml artifact (C:\Windows\System32\WDI\LogFiles\StartupInfo) records the first 90 seconds of user logon process activity and can reveal useful IoCs—such as user SID, parent/child PIDs, command lines, timestamps, and resource usage—enabling detection of registry-based PowerShell Empire persistence, while noting that WMI-based persistence can execute outside that 90-second window and evade this specific artifact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
