Reporting

Is there a way to monitor all program that are in Auto Run on Startup?

Kitteh
Path Finder

I am trying to find all programs that are set to auto run upon startup but however I've tried the registry key under Local Machine > Software > Microsoft > Windows > Current Version > Run, there are far less than what I thought it would. But however Task Manager shows much more auto run programs as shown in the attached image, how do I have splunk to monitor this?alt text

0 Karma
1 Solution

spayneort
Contributor

You can use Sysinternals Autoruns to see what is set to start automatically.

https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

Here is a script to convert the output of that tool into Splunk or Sysmon format. It recommends disabling all of the "Hide" options in Autoruns for best results.

https://github.com/dstaulcu/AutorunsToSysmon/

The "Splunking the Endpoint" session from .conf 2015 went over Autoruns registry monitoring and has a link to some configuration files on slide #8.

http://conf.splunk.com/session/2015/conf2015_Jbrodsky_Splunk_SecurityComplinace_SplunkingTheEndpoint...

View solution in original post

0 Karma

spayneort
Contributor

You can use Sysinternals Autoruns to see what is set to start automatically.

https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

Here is a script to convert the output of that tool into Splunk or Sysmon format. It recommends disabling all of the "Hide" options in Autoruns for best results.

https://github.com/dstaulcu/AutorunsToSysmon/

The "Splunking the Endpoint" session from .conf 2015 went over Autoruns registry monitoring and has a link to some configuration files on slide #8.

http://conf.splunk.com/session/2015/conf2015_Jbrodsky_Splunk_SecurityComplinace_SplunkingTheEndpoint...

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...