LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

Why does a Sysmon rule that includes registry changes under CurrentVersion\Run catch so much malware?

Because the Run keys start their listed programs automatically at every logon, which makes them the simplest and most common way for malware to survive a reboot (persistence).

Persistence via the Run key: malware writes the key once, Windows starts it at every logon; Sysmon event 13 logs the write and event 1 each start

* One registry write buys a restart at every logon, and both steps leave Sysmon events. *

The keys HKCU\Software\Microsoft\Windows\CurrentVersion\Run and its HKLM counterpart (plus RunOnce) hold a list of programs Windows launches when a user logs on. Writing one value there requires no exploit, only normal user rights for the HKCU key, so commodity malware, remote-access tools and adware all use it. MITRE ATT&CK lists it as a persistence technique (originally T1060, today T1547.001).

A Sysmon rule with onmatch="include" and TargetObject contains CurrentVersion\Run logs every write there (event 13, registry value set), including the process that did it. Legitimate writes are few and recognisable (an updater, a chat client), so an unexpected binary in AppData registering itself stands out immediately.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026