[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$foP_ZfJ26pJkZldgXcbIRoymDMGPHO4PF2G7h1Lf-Mv0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":38,"aiConfidence":38,"updatedAt":57,"createdAt":57,"_status":56},1271,"What is the recommended defense against Logon Scripts persistence attacks?","The primary defense is to monitor changes to the registry key `HKCR\\Environment\\UserInitMprLogonScript`. Any unauthorized creation or modification of this key should trigger an alert. Additionally, organizations should enforce strict access controls on the registry and use endpoint detection and response (EDR) tools to detect suspicious logon script executions.\n\n---\n**Related reading:**\n- [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence) — original article\n- [Penetration Techniques - Obtaining Net-NTLM Hash via HTTP Protocol](\u002Fnews\u002Fpenetration-techniques-obtaining-net-ntlm-hash-via-http-protocol)\n- [Webmin\u003C=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\n- [Pupy Exploitation Analysis - Features on Windows Platform](\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform)","\u003Cp>The primary defense is to monitor changes to the registry key `HKCR\\Environment\\UserInitMprLogonScript`. Any unauthorized creation or modification of this key should trigger an alert. Additionally, organizations should enforce strict access controls on the registry and use endpoint detection and response (EDR) tools to detect suspicious logon script executions.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [Use Logon Scripts to maintain persistence](\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence) — original article\u003Cbr>- [Penetration Techniques - Obtaining Net-NTLM Hash via HTTP Protocol](\u002Fnews\u002Fpenetration-techniques-obtaining-net-ntlm-hash-via-http-protocol)\u003Cbr>- [Webmin&lt;=1.920-Unauthenticated_RCE(CVE-2019-15107) Exploitation Test](\u002Fnews\u002Fwebmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test)\u003Cbr>- [Pupy Exploitation Analysis - Features on Windows Platform](\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-logon-scripts-to-maintain-persistence\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-recommended-defense-against-logon-scripts-persistence-attacks-1777477604977","defense, registry monitoring, UserInitMprLogonScript, endpoint security, EDR",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":20,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":40,"qaPairs":41,"meta":53,"updatedAt":54,"createdAt":55,"_status":56},298,"Use Logon Scripts to maintain persistence","use-logon-scripts-to-maintain-persistence","Learn how Logon Scripts execute before antivirus, enabling persistence and bypassing security. Includes WMI bypass and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article continues the series on backdoor exploitation methods, focusing on the use of Logon Scripts. During my research, I discovered a particular technique where scripts execute before antivirus software, allowing them to bypass antivirus interception of sensitive operations. This article will detail this technique.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some antivirus software can start before Logon Scripts.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Usage of Logon Scripts\u003C\u002Fli>\u003Cli>Bypassing 360's interception of WMI calls\u003C\u002Fli>\u003Cli>Special Techniques\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of Logon Scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The idea originates from Adam@Hexacorn, with the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2014\u002F11\u002F14\u002Fbeyond-good-ol-run-key-part-18\u002F\u003C\u002Fp>\u003Ch3>Brief introduction to the usage of Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCU\\Environment\\\u003C\u002Fp>\u003Cp>Create string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set key value to absolute path of bat: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016714386_0_81861fd612.jpeg\">\u003C\u002Fp>\u003Cp>The content of the bat is as follows:\u003C\u002Fp>\u003Cp>start calc.exe\u003C\u002Fp>\u003Cp>Log off, log on\u003C\u002Fp>\u003Cp>Execute script 11.bat, calculator pops up\u003C\u002Fp>\u003Ch2>0x03 Bypass 360's interception of modifying environment variables via WMI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article 'Use CLR to maintain persistence', the method of using wmic to modify environment variables\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, 360 will intercept WMI operations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016717261_1_b0cdc42c34.jpeg\">\u003C\u002Fp>\u003Cp>In fact, adding environment variables via WMI is equivalent to creating key-values in the registry HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Therefore, WMI operations can be replaced by writing to the registry\u003C\u002Fp>\u003Cp>The above WMI command can be replaced with the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Special Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Originating from a unique idea of mine\u003C\u002Fp>\u003Cp>During my research on this technique, I had an interesting thought: Do Logon Scripts start before other programs?\u003C\u002Fp>\u003Cp>If so, do they also start before antivirus software?\u003C\u002Fp>\u003Cp>Now, let's begin my test:\u003C\u002Fp>\u003Ch3>1. Enter the following code in cmd:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As expected, it was blocked\u003C\u002Fp>\u003Ch3>2. Setting Logon Scripts\u003C\u002Fh3>\u003Cp>The code for 11.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003Cbr>reg query HKEY_CURRENT_USER\\Environment \u002FV test\u003Cbr>pause\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enabling Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Create a string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set the key value to the absolute path of the bat file: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>Since calling WMI will be blocked, it can be implemented via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" UserInitMprLogonScript -value \"c:\\test\\11.bat\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log off, log back in, and test\u003C\u002Fh3>\u003Cp>If the registry HKCR\\Environment\\ is successfully written with the key value test REG_SZ I run faster!, it indicates that Logon Scripts execute before antivirus software, bypassing its restrictions\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016723345_2_d09ecdd162.png\">\u003C\u002Fp>\u003Cp>Test successful, verifying our conclusion\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor registry key HKCR\\Environment\\UserInitMprLogonScript\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the usage of Logon Scripts and introduces a special application: Logon Scripts can execute before antivirus software, bypassing its interception of sensitive operations.\u003C\u002Fp>\u003Cp>From a defensive perspective, vigilance should be maintained against this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article continues the series on backdoor exploitation methods, focusing on the use of Logon Scripts. During my research, I discovered a particular technique where scripts execute before antivirus software, allowing them to bypass antivirus interception of sensitive operations. This article will detail this technique.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some antivirus software can start before Logon Scripts.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cul>\u003Cli>Usage of Logon Scripts\u003C\u002Fli>\u003Cli>Bypassing 360's interception of WMI calls\u003C\u002Fli>\u003Cli>Special Techniques\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of Logon Scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The idea originates from Adam@Hexacorn, with the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2014\u002F11\u002F14\u002Fbeyond-good-ol-run-key-part-18\u002F\u003C\u002Fp>\u003Ch3>Brief introduction to the usage of Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCU\\Environment\\\u003C\u002Fp>\u003Cp>Create string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set key value to absolute path of bat: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016714386_0_81861fd612-1.jpeg\">\u003C\u002Fp>\u003Cp>The content of the bat is as follows:\u003C\u002Fp>\u003Cp>start calc.exe\u003C\u002Fp>\u003Cp>Log off, log on\u003C\u002Fp>\u003Cp>Execute script 11.bat, calculator pops up\u003C\u002Fp>\u003Ch2>0x03 Bypass 360's interception of modifying environment variables via WMI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>As mentioned in the previous article 'Use CLR to maintain persistence', the method of using wmic to modify environment variables\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"COR_ENABLE_PROFILING\",username=\"%username%\",VariableValue=\"1\"\u003Cbr>\u003Cbr>wmic ENVIRONMENT create name=\"COR_PROFILER\",username=\"%username%\",VariableValue=\"{11111111-1111-1111-1111-111111111111}\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, 360 will intercept WMI operations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016717261_1_b0cdc42c34-1.jpeg\">\u003C\u002Fp>\u003Cp>In fact, adding environment variables via WMI is equivalent to creating key-values in the registry HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Therefore, WMI operations can be replaced by writing to the registry\u003C\u002Fp>\u003Cp>The above WMI command can be replaced with the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" COR_ENABLE_PROFILING -value \"1\" -propertyType string | Out-Null\u003Cbr>\u003Cbr>New-ItemProperty \"HKCU:\\Environment\\\" COR_PROFILER -value \"{11111111-1111-1111-1111-111111111111}\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Special Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Originating from a unique idea of mine\u003C\u002Fp>\u003Cp>During my research on this technique, I had an interesting thought: Do Logon Scripts start before other programs?\u003C\u002Fp>\u003Cp>If so, do they also start before antivirus software?\u003C\u002Fp>\u003Cp>Now, let's begin my test:\u003C\u002Fp>\u003Ch3>1. Enter the following code in cmd:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As expected, it was blocked\u003C\u002Fp>\u003Ch3>2. Setting Logon Scripts\u003C\u002Fh3>\u003Cp>The code for 11.bat is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic ENVIRONMENT create name=\"test\",username=\"%username%\",VariableValue=\"I run faster!\"\u003Cbr>reg query HKEY_CURRENT_USER\\Environment \u002FV test\u003Cbr>pause\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enabling Logon Scripts\u003C\u002Fh3>\u003Cp>Registry path: HKCR\\Environment\\\u003C\u002Fp>\u003Cp>Create a string key value: UserInitMprLogonScript\u003C\u002Fp>\u003Cp>Set the key value to the absolute path of the bat file: c:\\test\\11.bat\u003C\u002Fp>\u003Cp>Since calling WMI will be blocked, it can be implemented via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ItemProperty \"HKCU:\\Environment\\\" UserInitMprLogonScript -value \"c:\\test\\11.bat\" -propertyType string | Out-Null\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log off, log back in, and test\u003C\u002Fh3>\u003Cp>If the registry HKCR\\Environment\\ is successfully written with the key value test REG_SZ I run faster!, it indicates that Logon Scripts execute before antivirus software, bypassing its restrictions\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016723345_2_d09ecdd162-1.png\">\u003C\u002Fp>\u003Cp>Test successful, verifying our conclusion\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Monitor registry key HKCR\\Environment\\UserInitMprLogonScript\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests the usage of Logon Scripts and introduces a special application: Logon Scripts can execute before antivirus software, bypassing its interception of sensitive operations.\u003C\u002Fp>\u003Cp>From a defensive perspective, vigilance should be maintained against this.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","Onedaysec",3,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":38,"canonicalUrl":38,"noIndex":39},"Logon Scripts Persistence: Bypass Antivirus with Pre-Execution","logon scripts, persistence, bypass antivirus, WMI interception, registry exploit, backdoor techniques, security evasion",null,false,[],{"docs":42,"hasNextPage":52},[43,44,45,46,4,47,48,49,50,51],1275,1274,1273,1272,1270,1269,1268,1267,1266,true,{"title":38,"description":38,"image":38},"2026-07-24T15:37:08.719Z","2026-07-23T16:02:42.266Z","draft","2026-07-23T16:17:47.280Z"]