Abusing Windows Telemetry for Persistence
ID: d2f5bffb-ee2a-5701-9d12-fdcb5af16e2d
STIX ID: report--d2f5bffb-ee2a-5701-9d12-fdcb5af16e2d
Feed Name: TrustedSec blog
Threat Score
This report describes a persistence technique that leverages the Windows CompatTelRunner.exe telemetry controller by adding keys under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\TelemetryController to run arbitrary executables as SYSTEM on client Windows versions; it explains configuration steps, internal run modes/validation, command invocation, and defensive implications (not visible in autoruns and requires monitoring of this registry area).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
