Run key persistence: what the registry alone will not tell you

A lab reconstruction of a user-level persistence case, and why the Run key timestamp is the least useful thing in the artifact set.

The scenario is deliberately mundane, because mundane is what you actually get: a workstation flagged by a single Sysmon alert, a user who "didn't install anything", and a Run key value called OneDriveSync pointing at a binary that is not OneDrive.

The interesting part is not finding the persistence. RegRipper finds it in four seconds. The interesting part is that almost every instinct about when it was planted turns out to be wrong.

The artifact that started it

[!] members only

The rest of this teardown — the full timeline, the complete IOC list and the detection rule with its tuning notes — is for members. Sign in if you have an account, or start a 7-day trial. No card is charged and none is collected up front.

sign insee what is included
Run key persistence: what the registry alone will not tell you — Security Artifacts