Quiz 2 Question 5 of 20

An EDR alert shows reg.exe adding a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run that points to %APPDATA%\Temp\update.exe. The file is unsigned and was created minutes earlier. Which type of malicious activity should the analyst report first?

Select an answer to reveal the explanation.

Motivation