logo

Backdoors & Breaches: Logon Scripts

ID: b777bf8e-b663-57af-bd74-5723c3997c85

STIX ID: report--b777bf8e-b663-57af-bd74-5723c3997c85

Feed Name: Black Hills Infosec Blog

Date Published: 2020-04-06

Date Updated: 2026-04-27

Author: BHIS

...
...

This post explains how attackers abuse Windows/Active Directory logon-script execution paths—such as Registry Run/RunOnce keys, startup folders, SYSVOL logon scripts, Group Policy Object modifications, and user ScriptPath changes—to gain execution, persistence, and lateral movement. It advises defenders to monitor key registry and filesystem locations, regularly audit NTFS and GPO permissions, and leverage tools like BloodHound to identify risky delegations and misconfigurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.