EmpireProject/Empire

[Feature Request] Start and Hide Within a Registry Key

Open

#1,204 opened on Aug 16, 2018

View on GitHub
 (8 comments) (0 reactions) (0 assignees)PowerShell (7,836 stars) (2,920 forks)batch import
enhancementhelp wanted

Description

Can you add the option to start up and hide completely within the registry inside a key and not as a script or dell or exe, anywhere else on disk, this is explained better by a report from trendmicro.

https://blog.trendmicro.com/trendlabs-security-intelligence/poweliks-malware-hides-in-windows-registry/

https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/TROJ_POWELIKS.A - shows the key near the bottom Thanks

Contributor guide