diff --git a/nursery/persist-via-startup-folder.yml b/nursery/persist-via-startup-folder.yml deleted file mode 100644 index 61299204..00000000 --- a/nursery/persist-via-startup-folder.yml +++ /dev/null @@ -1,23 +0,0 @@ -rule: - meta: - name: persist via startup folder - namespace: persistence/file-system - authors: - - j.j.vannielen@utwente.nl - scopes: - static: function - dynamic: call - att&ck: - - Persistence::Boot or Logon Autostart Execution::Registry Run Keys / Startup Folder [T1547.001] - references: - - https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1547-boot-or-logon-autostart-execution/registry-run-keys-startup-folder - features: - - and: - - or: - - match: copy file - - match: move file - - match: write file on Windows - - or: - - string: /Microsoft\\Windows\\Start Menu\\Programs\\Startup\\/i - - string: /Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\/i - - string: /WINNT\\Profiles\\All Users\\Start Menu\\Programs\\Startup\\/i