Reporting

Is there a way to monitor all program that are in Auto Run on Startup?

Kitteh
Path Finder

I am trying to find all programs that are set to auto run upon startup but however I've tried the registry key under Local Machine > Software > Microsoft > Windows > Current Version > Run, there are far less than what I thought it would. But however Task Manager shows much more auto run programs as shown in the attached image, how do I have splunk to monitor this?alt text

0 Karma
1 Solution

spayneort
Contributor

You can use Sysinternals Autoruns to see what is set to start automatically.

https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

Here is a script to convert the output of that tool into Splunk or Sysmon format. It recommends disabling all of the "Hide" options in Autoruns for best results.

https://github.com/dstaulcu/AutorunsToSysmon/

The "Splunking the Endpoint" session from .conf 2015 went over Autoruns registry monitoring and has a link to some configuration files on slide #8.

http://conf.splunk.com/session/2015/conf2015_Jbrodsky_Splunk_SecurityComplinace_SplunkingTheEndpoint...

View solution in original post

0 Karma

spayneort
Contributor

You can use Sysinternals Autoruns to see what is set to start automatically.

https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

Here is a script to convert the output of that tool into Splunk or Sysmon format. It recommends disabling all of the "Hide" options in Autoruns for best results.

https://github.com/dstaulcu/AutorunsToSysmon/

The "Splunking the Endpoint" session from .conf 2015 went over Autoruns registry monitoring and has a link to some configuration files on slide #8.

http://conf.splunk.com/session/2015/conf2015_Jbrodsky_Splunk_SecurityComplinace_SplunkingTheEndpoint...

0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Announcing the General Availability of Splunk Enterprise Security 8.1!

We are pleased to announce the general availability of Splunk Enterprise Security 8.1. Splunk becomes the only ...

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...