A forensic analyst discovers an unusual entry in the Windows Registry under 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which persistence mechanism does this represent?
The Run key is a Windows AutoStart Extensibility Point (ASEP) located in both HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, causing the referenced executable to launch each time a user logs on. An unusual entry here, often a command line pointing to a portable executable in a temp directory, is a classic persistence mechanism used by malware. Because the Run key is queried at logon and is a single value, it is one of the simplest and most frequently abused persistences in Windows, and its presence is a strong indicator of compromise when the entry is not associated with a legitimate installed program.
Why this answer
The registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' is a standard Windows Registry Run key that automatically launches specified programs when a user logs in. This is a well-known persistence mechanism used by both legitimate software and malware to maintain foothold on a system. The presence of an unusual entry here indicates an attempt to achieve persistence via the registry.
Exam trap
EC-Council CHFI often tests the distinction between user-specific (HKCU) and system-wide (HKLM) Run keys, and candidates may confuse the Run key with other persistence mechanisms like scheduled tasks or services, but the key path explicitly identifies it as a Registry Run key.
How to eliminate wrong answers
Option B is wrong because service installation uses the Service Control Manager (SCM) and registry keys under 'HKLM\System\CurrentControlSet\Services' or 'HKCU\System\CurrentControlSet\Services', not the 'Run' key. Option C is wrong because scheduled tasks are configured via the Task Scheduler (stored in %SystemRoot%\Tasks or the Task Scheduler XML files), not through the 'Run' registry key. Option D is wrong because the Startup folder is a physical folder located at '%AppData%\Microsoft\Windows\Start Menu\Programs\Startup' (or the All Users variant), not a registry key.