Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a malicious startup item?

A malicious startup item is a file, shortcut or setting intended to launch unauthorised code when a system or user session starts. Automatic startup is normal for many applications, so an unfamiliar entry is not enough to establish malware.

Connect the entry to its context

Preserve the startup location, stable identifier, target command and arguments, creation and modification times, and whether it applies to one user or the whole system. Identify the account or process that created it and retain the target file before removal.

Mechanisms vary by platform and include startup folders, login items, registry settings, shell profiles, launch agents and boot configuration. Names can imitate trusted software, while a legitimate-looking target may use altered arguments.

Prove that the trigger occurred

An entry cannot run until its relevant startup event occurs. Align it with boot or login records, then seek process, file and network evidence of execution. On shared systems, identify the profile involved and which other accounts could modify it.

Presence proves automatic-start capability, not successful execution or malicious purpose. Compare the entry with authorised installations and normal baselines, and record responder changes.

Key takeaway

Preserve the startup entry, target and creator, then connect it to an actual boot or login and resulting activity before calling it used persistence.

Reference: CIM-112Cyber Incidents & Offender Methods