logo

Abusing Windows Telemetry for Persistence

ID: d2f5bffb-ee2a-5701-9d12-fdcb5af16e2d

STIX ID: report--d2f5bffb-ee2a-5701-9d12-fdcb5af16e2d

Feed Name: TrustedSec blog

Threat Score
35/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report describes a persistence technique that leverages the Windows CompatTelRunner.exe telemetry controller by adding keys under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\TelemetryController to run arbitrary executables as SYSTEM on client Windows versions; it explains configuration steps, internal run modes/validation, command invocation, and defensive implications (not visible in autoruns and requires monitoring of this registry area).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.