Reporting

Is there a way to monitor all program that are in Auto Run on Startup?

Kitteh
Path Finder

I am trying to find all programs that are set to auto run upon startup but however I've tried the registry key under Local Machine > Software > Microsoft > Windows > Current Version > Run, there are far less than what I thought it would. But however Task Manager shows much more auto run programs as shown in the attached image, how do I have splunk to monitor this?alt text

0 Karma
1 Solution

spayneort
Contributor

You can use Sysinternals Autoruns to see what is set to start automatically.

https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

Here is a script to convert the output of that tool into Splunk or Sysmon format. It recommends disabling all of the "Hide" options in Autoruns for best results.

https://github.com/dstaulcu/AutorunsToSysmon/

The "Splunking the Endpoint" session from .conf 2015 went over Autoruns registry monitoring and has a link to some configuration files on slide #8.

http://conf.splunk.com/session/2015/conf2015_Jbrodsky_Splunk_SecurityComplinace_SplunkingTheEndpoint...

View solution in original post

0 Karma

spayneort
Contributor

You can use Sysinternals Autoruns to see what is set to start automatically.

https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

Here is a script to convert the output of that tool into Splunk or Sysmon format. It recommends disabling all of the "Hide" options in Autoruns for best results.

https://github.com/dstaulcu/AutorunsToSysmon/

The "Splunking the Endpoint" session from .conf 2015 went over Autoruns registry monitoring and has a link to some configuration files on slide #8.

http://conf.splunk.com/session/2015/conf2015_Jbrodsky_Splunk_SecurityComplinace_SplunkingTheEndpoint...

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...