T1547.001 Registry Run Keys / Startup Folder — MITRE Technique
CASE-20260907-4B17
MEDIUM
OPEN
Assignee: unassigned · Opened 7h ago
Opened from technique T1547.001 Registry Run Keys / Startup Folder
🔄 Pivot:📁 technique
Entities
1
linked to case
IoCs
0
indicators
Entity types
1
dimensions
Evidence events
2
chain of custody
➕ Add anything to this case
Attach any entity — region, country, APT, source, MITRE technique, IoC, nation-state, campaign, data point, mission domain, CVE, malware, ransomware — and all linked entities are pulled in automatically.
⚙ MITRE Technique (1)
🤖 Case Operations
📜 Chain of Evidence (tamper-evident, hash-chained)
| When | Actor | Action | Entity | Source | Hash |
|---|---|---|---|---|---|
| 2026-09-06 23:06:55 | analyst | add | technique: T1547.001 Registry Run Keys / | manual · primary | 5562eb0452 |
| 2026-09-06 23:06:55 | analyst | open | technique: T1547.001 Registry Run Keys / | analyst · case created | 190ee477a5 |
Each record's hash chains to the previous, so any tampering is detectable. Export the full trail via the Evidence report.
📝 Case Notes (0)
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Attach all related IoCs as artifacts
- Run a response playbook per case type
- Escalate to legal when needed