24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
AF-2DFB-REG · Windows Registry

Registry Persistence

DOWNLOADABLE registry export (.reg). The Run keys hold legitimate entries (OneDrive, SecurityHealth, Realtek) alongside a malicious persistence entry: an unsigned autorun running from C:\Users\Public. Do not mistake legitimate entries for malware.

Scenario

A RegRipper-style registry export from a workstation (HKLM/HKCU Run + LastWrite times). Most autoruns are legitimate: signed apps under System32, Program Files or AppData. One entry is malicious: it masquerades as a legitimate Windows update component but runs an unsigned exe from C:\Users\Public and its LastWrite time coincides with the incident. Skill: not reporting legitimate signed entries (OneDrive etc.) as malware; correctly catching the unsigned/Public-path persistence.

Anti-forensics techniques

  • Entry masquerade (legitimate-component imitation)
  • Noise: many legitimate autoruns (decoy)
  • Unsigned/Public-path persistence

Provided artifacts

  • Registry export (.reg, Run keys)

Sample questions

  1. q1: Name of the malicious value providing persistence?
  2. q2: The file path it executes?
  3. trap1: Do NOT report a legitimate entry (OneDrive) as malware.

Soundness trap

Entries like OneDrive, SecurityHealth are legitimate and signed; reporting one as malware is heavily penalized. The real persistence is only the unsigned autorun under the Public path.

Scoring

Persistence triage accuracy + legitimate-entry decoy resistance (soundness).

DOWNLOADABLE

Download and solve

Download artifact

The answer key is hidden (scored set); the flag is encrypted, you must decrypt it.

Solve in your browser

DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
← Catalog
Privacy
KVKK
GDPR
Cookies
Terms