| Technique | Registry Location | Notes |
| Accessibility Features | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options | |
| Execution/Persistence | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode | |
| Pass The Hash | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy | |
| Credential Access | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages | |
| Persistence | HKCU\Control Panel\Desktop\ | Screensaver |
| Persistence | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\TimeProviders\ | Time providers |
| Persistence | (Auto-Runs) Classification | |
| (Auto-Logon) Classification | |
| (Office Addiin) Classification | |
| (IE plugin) Classification | |
| (Explore SideBar) Classification | |
| (Exploer Shell Startup) Classification | |
| (Known DLLs) Classification | |
| (Boot Execute) Classification | |
| (USB Storage) Classification | |
| (Application Compat) Classification | |
| (Run Keys) Classification | |