LAB 644 – Response: Detecting Malware in the Windows Startup Folder (NEW)

Course Overview


Persistence mechanisms let attackers stick around unless you know how to find them. In this lab, dive into real-world scenarios to detect scheduled tasks, registry tampering, and other persistence techniques.

After completing this lab, learners will have the knowledge and skill to:

  • Detect persistence tactics (T1053, T1547) in Windows environments
  • Investigate registry keys, startup folders, and services
  • Trace indicators of compromise using MITRE ATT&CK
  • Respond with containment and eradication actions

Looking To Learn More?

Request more information on our courses and labs.

* required


Course Details

Course Number: LAB 644
Course Duration: 5 minutes
Course CPE Credits: 0.1

NICE Work Role Category

Available Languages

  • English