.. / Runonce.exe
Star


Paths:


Resources:
https://twitter.com/pabraeken/status/990717080805789697
https://cmatskas.com/configure-a-runonce-task-on-windows/

Acknowledgement:
Pierre-Alexandre Braeken - @pabraeken


Detection:
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\YOURKEY



Execute

Executes a Run Once Task that has been configured in the registry
Runonce.exe /AlternateShellStartup
Usecase:Persistence, bypassing defensive counter measures
Privileges required:Administrator
OS:Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1218