Skip to main content
← Back to Demos
Malware intermediate · 15 min

Sandbox observes Run-key persistence installation

Persistence is what turns a one-time compromise into a lasting foothold: malware writes an entry to a Windows Registry Run key so it relaunches automatically at every logon. This demo uses a benign executable that performs the same run-key write to illustrate the behavior. Adaptive Sandbox observes the registry write inside an isolated environment and reports the persistence mechanism together with its full command line, letting analysts see exactly how an implant would survive reboots. The payload performs only a benign run-key write, so no real malware or system modification occurs outside the sandbox.

Attack Technique

Registry persistence

MITRE ATT&CK

T1547.001 ↗

Platforms

linuxmacoswindows

File Types

.sh

MetaDefender Capabilities

Adaptive Sandbox
--- ---