logo

Explore Expel’s auto remediations: Delete registry key

ID: bc83e414-5b24-5200-bb69-ac8e481b0bad

STIX ID: report--bc83e414-5b24-5200-bb69-ac8e481b0bad

Feed Name: Expel Blog

Threat Score
50/100

Date Published: 2025-06-24

Date Updated: 2026-04-27

Author: Jake Godgart

...
...

This document explains Expel's 'delete registry key' auto-remediation for removing Windows Registry-based persistence used by malware (illustrated with an 'InfoGrabber' stealer example). It details the SOC workflow — detection of suspicious autorun entries, careful validation to avoid breaking legitimate functionality, customer approval, execution via EDR, and confirmation — and highlights risks, common targets, and when the action is appropriate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.