Explore Expel’s auto remediations: Delete registry key
ID: bc83e414-5b24-5200-bb69-ac8e481b0bad
STIX ID: report--bc83e414-5b24-5200-bb69-ac8e481b0bad
Feed Name: Expel Blog
Threat Score
This document explains Expel's 'delete registry key' auto-remediation for removing Windows Registry-based persistence used by malware (illustrated with an 'InfoGrabber' stealer example). It details the SOC workflow — detection of suspicious autorun entries, careful validation to avoid breaking legitimate functionality, customer approval, execution via EDR, and confirmation — and highlights risks, common targets, and when the action is appropriate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
