Learn to use the AutoRuns PowerShell module to detect persistence mechanisms that use the Registry.
One crucial step that malware does upon successful execution on a target machine is to ensure that it can stay there even after a reboot or removal attempt. This is possible using various techniques, collectively called "malware persistence mechanisms".
https://tryhackme.com/room/registrype...
#tryhackme