LAB 644 – Response: Detecting Malware in the Windows Startup Folder (NEW)
Course Overview
Persistence mechanisms let attackers stick around unless you know how to find them. In this lab, dive into real-world scenarios to detect scheduled tasks, registry tampering, and other persistence techniques.
After completing this lab, learners will have the knowledge and skill to:
- Detect persistence tactics (T1053, T1547) in Windows environments
- Investigate registry keys, startup folders, and services
- Trace indicators of compromise using MITRE ATT&CK
- Respond with containment and eradication actions
Looking To Learn More?
Request more information on our courses and labs.
* required

Course Details
Course Number: LAB 644
Course Duration: 5 minutes
Course CPE Credits: 0.1
NICE Work Role Category
Available Languages
- English