[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUoqt_ItUZPHzRdXj9HCa5tzmEmKirjeFSNZN9k9qGuU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":38,"aiConfidence":38,"updatedAt":57,"createdAt":57,"_status":56},1275,"What is the recommended defense against Logon Scripts persistence?","The primary defense is to monitor the registry key `HKCU\\Environment\\UserInitMprLogonScript` for any unauthorized modifications. Unusual or unexpected scripts set as the value indicate a potential persistence mechanism. Additionally, security teams should track changes to environment variables under `HKCU\\Environment`. For more context, refer to the [Logon Scripts article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).","\u003Cp>The primary defense is to monitor the registry key `HKCU\\Environment\\UserInitMprLogonScript` for any unauthorized modifications. Unusual or unexpected scripts set as the value indicate a potential persistence mechanism. Additionally, security teams should track changes to environment variables under `HKCU\\Environment`. For more context, refer to the [Logon Scripts article](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-recommended-defense-against-logon-scripts-persistence-1777479956871","defense, registry monitoring, UserInitMprLogonScript, persistence detection",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":20,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":40,"qaPairs":41,"meta":53,"updatedAt":54,"createdAt":55,"_status":56},298,"Use Logon Scripts to maintain persistence","use-logon-scripts-to-maintain-persistence","Learn how Logon Scripts execute before antivirus, enabling persistence and bypassing security. Includes WMI bypass and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article continues the series on backdoor exploitation methods, focusing on the use of Logon Scripts. During my research, I discovered a particular technique where scripts execute before antivirus software, allowing them to bypass antivirus interception of sensitive operations. This article will detail this technique.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some antivirus software can start before Logon Scripts.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Usage of Logon Scripts\u003C\u002Fli>\u003Cli>Bypassing 360's interception of WMI calls\u003C\u002Fli>\u003Cli>Special Techniques\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of Logon Scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The idea originates from Adam@Hexacorn, with the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2014\u002F11\u002F14\u002Fbeyond-good-ol-run-key-part-18\u002F\u003C\u002Fp>\u003Ch3>Brief introduction to the usage of Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCU\\Environment\\\u003C\u002Fp>\u003Cp>Create string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set key value to absolute path of bat: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016714386_0_81861fd612.jpeg\">\u003C\u002Fp>\u003Cp>The content of the bat is as follows:\u003C\u002Fp>\u003Cp>start calc.exe\u003C\u002Fp>\u003Cp>Log off, log on\u003C\u002Fp>\u003Cp>Execute script 11.bat, calculator pops up\u003C\u002Fp>\u003Ch2>0x03 Bypass 360's interception of modifying environment variables via WMI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article 'Use CLR to maintain persistence', the method of using wmic to modify environment variables\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, 360 will intercept WMI operations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016717261_1_b0cdc42c34.jpeg\">\u003C\u002Fp>\u003Cp>In fact, adding environment variables via WMI is equivalent to creating key-values in the registry HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Therefore, WMI operations can be replaced by writing to the registry\u003C\u002Fp>\u003Cp>The above WMI command can be replaced with the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Special Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Originating from a unique idea of mine\u003C\u002Fp>\u003Cp>During my research on this technique, I had an interesting thought: Do Logon Scripts start before other programs?\u003C\u002Fp>\u003Cp>If so, do they also start before antivirus software?\u003C\u002Fp>\u003Cp>Now, let's begin my test:\u003C\u002Fp>\u003Ch3>1. Enter the following code in cmd:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As expected, it was blocked\u003C\u002Fp>\u003Ch3>2. Setting Logon Scripts\u003C\u002Fh3>\u003Cp>The code for 11.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003Cbr>reg query HKEY_CURRENT_USER\\Environment \u002FV test\u003Cbr>pause\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enabling Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Create a string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set the key value to the absolute path of the bat file: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>Since calling WMI will be blocked, it can be implemented via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" UserInitMprLogonScript -value \"c:\\test\\11.bat\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log off, log back in, and test\u003C\u002Fh3>\u003Cp>If the registry HKCR\\Environment\\ is successfully written with the key value test REG_SZ I run faster!, it indicates that Logon Scripts execute before antivirus software, bypassing its restrictions\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016723345_2_d09ecdd162.png\">\u003C\u002Fp>\u003Cp>Test successful, verifying our conclusion\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor registry key HKCR\\Environment\\UserInitMprLogonScript\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the usage of Logon Scripts and introduces a special application: Logon Scripts can execute before antivirus software, bypassing its interception of sensitive operations.\u003C\u002Fp>\u003Cp>From a defensive perspective, vigilance should be maintained against this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article continues the series on backdoor exploitation methods, focusing on the use of Logon Scripts. During my research, I discovered a particular technique where scripts execute before antivirus software, allowing them to bypass antivirus interception of sensitive operations. This article will detail this technique.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some antivirus software can start before Logon Scripts.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Usage of Logon Scripts\u003C\u002Fli>\u003Cli>Bypassing 360's interception of WMI calls\u003C\u002Fli>\u003Cli>Special Techniques\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of Logon Scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The idea originates from Adam@Hexacorn, with the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2014\u002F11\u002F14\u002Fbeyond-good-ol-run-key-part-18\u002F\u003C\u002Fp>\u003Ch3>Brief introduction to the usage of Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCU\\Environment\\\u003C\u002Fp>\u003Cp>Create string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set key value to absolute path of bat: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016714386_0_81861fd612-1.jpeg\">\u003C\u002Fp>\u003Cp>The content of the bat is as follows:\u003C\u002Fp>\u003Cp>start calc.exe\u003C\u002Fp>\u003Cp>Log off, log on\u003C\u002Fp>\u003Cp>Execute script 11.bat, calculator pops up\u003C\u002Fp>\u003Ch2>0x03 Bypass 360's interception of modifying environment variables via WMI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article 'Use CLR to maintain persistence', the method of using wmic to modify environment variables\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, 360 will intercept WMI operations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016717261_1_b0cdc42c34-1.jpeg\">\u003C\u002Fp>\u003Cp>In fact, adding environment variables via WMI is equivalent to creating key-values in the registry HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Therefore, WMI operations can be replaced by writing to the registry\u003C\u002Fp>\u003Cp>The above WMI command can be replaced with the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Special Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Originating from a unique idea of mine\u003C\u002Fp>\u003Cp>During my research on this technique, I had an interesting thought: Do Logon Scripts start before other programs?\u003C\u002Fp>\u003Cp>If so, do they also start before antivirus software?\u003C\u002Fp>\u003Cp>Now, let's begin my test:\u003C\u002Fp>\u003Ch3>1. Enter the following code in cmd:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As expected, it was blocked\u003C\u002Fp>\u003Ch3>2. Setting Logon Scripts\u003C\u002Fh3>\u003Cp>The code for 11.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003Cbr>reg query HKEY_CURRENT_USER\\Environment \u002FV test\u003Cbr>pause\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enabling Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Create a string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set the key value to the absolute path of the bat file: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>Since calling WMI will be blocked, it can be implemented via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" UserInitMprLogonScript -value \"c:\\test\\11.bat\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log off, log back in, and test\u003C\u002Fh3>\u003Cp>If the registry HKCR\\Environment\\ is successfully written with the key value test REG_SZ I run faster!, it indicates that Logon Scripts execute before antivirus software, bypassing its restrictions\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016723345_2_d09ecdd162-1.png\">\u003C\u002Fp>\u003Cp>Test successful, verifying our conclusion\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor registry key HKCR\\Environment\\UserInitMprLogonScript\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the usage of Logon Scripts and introduces a special application: Logon Scripts can execute before antivirus software, bypassing its interception of sensitive operations.\u003C\u002Fp>\u003Cp>From a defensive perspective, vigilance should be maintained against this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","Onedaysec",3,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":38,"canonicalUrl":38,"noIndex":39},"Logon Scripts Persistence: Bypass Antivirus with Pre-Execution","logon scripts, persistence, bypass antivirus, WMI interception, registry exploit, backdoor techniques, security evasion",null,false,[],{"docs":42,"hasNextPage":52},[4,43,44,45,46,47,48,49,50,51],1274,1273,1272,1271,1270,1269,1268,1267,1266,true,{"title":38,"description":38,"image":38},"2026-07-24T15:37:08.719Z","2026-07-23T16:02:42.266Z","draft","2026-07-23T16:17:48.939Z"]