← Back to Demos
Malware intermediate · 15 min
Sandbox observes Run-key persistence installation
Persistence is what turns a one-time compromise into a lasting foothold: malware writes an entry to a Windows Registry Run key so it relaunches automatically at every logon. This demo uses a benign executable that performs the same run-key write to illustrate the behavior. Adaptive Sandbox observes the registry write inside an isolated environment and reports the persistence mechanism together with its full command line, letting analysts see exactly how an implant would survive reboots. The payload performs only a benign run-key write, so no real malware or system modification occurs outside the sandbox.
Attack Technique
Registry persistence
MITRE ATT&CK
T1547.001 ↗Platforms
linuxmacoswindows
File Types
.sh
MetaDefender Capabilities
Adaptive Sandbox