Forewarned is Forearmed: Detecting Windows Registry Attacks
About this webinar
You probably know that hackers have been using the registry’s Run and RunOnce keys for decades to automatically start their malware when a user logs on. While those keys are still being used in attacks, there are many others you need to know about as well. In this webinar, Windows security expert Randy Franklin Smith will shine a light into several dark corners of the registry that bad guys are now exploiting.
In particular, we’ll review how the bad guys are exploiting the registry for privilege elevation, and the most recent way bad guys are leveraging the registry — as a storage location for their code, making their malware file-less.
In this webinar, Randy will show:
- Where to find up-to-date and complete lists of registry keys used for persistence – a list that keeps growing as years go by
- Utilities for monitoring the registry
- How to use Windows Auditing and the Security Log to monitor the registry
- How bad guys hide code in the registry
- Ways bad guys have elevated their privileges via vulnerable registry keys
- How bad guys have injected malicious DLLs into legitimate processes via other registry keys
CEO, Monterey Technology Group, Inc.
Live Demo: Netwrix Auditor – Data Discovery & Classification Edition
Meet Netwrix Auditor – Data Discovery and Classification Edition, which provides complete visibility into where sensitive files are, what content is inside them, who can access the files and who actually uses them.
Join us and see how you can:
- Identify and classify the sensitive data you store
- Spot any sensitive data that surfaces outside of a secure location
- Prove the effectiveness of your data security controls to auditors
- And more