Backdoors & Breaches: Logon Scripts
ID: b777bf8e-b663-57af-bd74-5723c3997c85
STIX ID: report--b777bf8e-b663-57af-bd74-5723c3997c85
Feed Name: Black Hills Infosec Blog
This post explains how attackers abuse Windows/Active Directory logon-script execution paths—such as Registry Run/RunOnce keys, startup folders, SYSVOL logon scripts, Group Policy Object modifications, and user ScriptPath changes—to gain execution, persistence, and lateral movement. It advises defenders to monitor key registry and filesystem locations, regularly audit NTFS and GPO permissions, and leverage tools like BloodHound to identify risky delegations and misconfigurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
