autoruns

Windows Privesc

Abusing Registry Autoruns for Windows Persistence and Privilege Escalation

How attackers abuse writable Run keys and other autorun locations for persistence and privesc, plus how blue teams detect it.
Tools & Defense

Hunting Windows Persistence: From Autoruns to WMI Event Subscriptions

A practical guide to planting, detecting, and analyzing Windows persistence across registry, services, tasks, and WMI.