A new file in a Windows Startup folder deserves investigation, but it is not proof of compromise. This guide helps defenders connect a file change to its creator, resolve what it would launch, and look for actual execution after logon.
Why it matters
Startup folders are a legitimate logon-launch mechanism that attackers can abuse for persistence. MITRE ATT&CK maps this behavior to T1547.001: Registry Run Keys / Startup Folder. Apply that mapping to supported behavior; a matching path alone is a hunting lead, not an incident verdict.
Enlarge the investigation poster
Explore the evidence chain
File change: Establish which process and account introduced the artifact. Launch target: Resolve shortcuts and scripts with approved static tooling, without opening or running them. Execution: Look for the resolved target and arguments in process telemetry around subsequent logons. Record uncertainty when telemetry is absent.
1. Confirm scope and telemetry
Start with a 24-hour window and affected devices, then expand deliberately. Collect Defender for Endpoint file and process events, or centrally collected Sysmon Event ID 11 (file creation) and Event ID 1 (process creation). Confirm collection configuration and retention first. Sysmon only reports events covered by its configuration; no matching event does not establish absence.
Common locations include a user's AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup folder and the shared ProgramData\Microsoft\Windows\Start Menu\Programs\Startup folder. Resolve actual paths on the endpoint; redirection and local configuration can change coverage. Include shortcuts, scripts and executables rather than filtering solely on file extension.
2. Find candidate writes with KQL
Read-only example: Run in Microsoft Defender XDR advanced hunting with Defender for Endpoint telemetry. Test and adapt this query only in an authorized environment. These examples are starting points, not tenant-tested production detections.
DeviceFileEvents
| where Timestamp > ago(24h)
| where FolderPath contains @"\Microsoft\Windows\Start Menu\Programs\Startup"
| project Timestamp, DeviceId, DeviceName, ActionType,
FolderPath, FileName, SHA1,
InitiatingProcessAccountName, InitiatingProcessFileName,
InitiatingProcessCommandLine, InitiatingProcessId,
InitiatingProcessCreationTime
| order by Timestamp desc
| take 200This intentionally broad path filter generates candidates, including possible similarly named directories. Verify the exact directory boundary before escalation. Examine ActionType instead of assuming every row represents creation; the portal's built-in schema lists supported action values. The 200-row limit is for triage, not a complete count. Remove or page through that limit during scoping. Hash fields can be empty and a shortcut's hash identifies the shortcut, not its target.
3. Search Sysmon in Splunk
Replace the index with your authorized Sysmon index. This version assumes your Windows/Sysmon extraction exposes EventCode and TargetFilename; inspect a known Event 11 record and map fields before running it. XML pipelines may name fields differently.
index=YOUR_SYSMON_INDEX EventCode=11 earliest=-24h latest=now
| where match(TargetFilename, "(?i)\\\\Microsoft\\\\Windows\\\\Start Menu\\\\Programs\\\\Startup\\\\")
| table _time Computer User Image ProcessGuid TargetFilename
| sort 0 - _time
| head 200The regular expression matches the directory separator after Startup to avoid a similarly prefixed folder name. Confirm escaping in your search editor against a known benign sample. Event 11 tells you about creation or overwrite; it does not tell you that the saved item subsequently executed. Missing user fields must not remove otherwise useful events from your investigation.
4. Resolve intent without launching the artifact
Preserve a copy using your approved evidence process. Record original path, collection time in UTC, hashes and collector identity. Inspect a shortcut's target, arguments and working directory using trusted static tooling. For scripts, review content without executing it. Trace the target's origin, signer, prevalence and recent changes. A valid signature increases context but is not an automatic safe verdict.
Correlate the writer with process telemetry. Sysmon ProcessGuid is preferable to a process ID alone; on Defender, retain device identity, process ID and creation time because process IDs are reused. Review the parent's command line and related downloads or installation activity.
5. Look for actual execution and compare explanations
Search process creation events for the resolved target on the same device around later logons. Compare the exact path, command line, account and timing, then inspect children and relevant network activity. A temporal match supports a hypothesis but does not independently prove the Startup folder caused the launch. Record whether execution is confirmed, plausible or unknown.
Illustrative benign example: An approved collaboration-tool installer creates a signed application's shortcut during a documented rollout. The same change appears on expected devices, and the application owner confirms the behavior. Close with evidence and a narrowly scoped exception.
Illustrative escalation example: An unexpected script host writes a shortcut pointing to a newly downloaded script under a user-writable directory. After logon, matching process telemetry shows that script launching another interpreter. This warrants escalation and deeper scoping; the sequence still does not establish data theft without additional evidence. Both examples are fictional teaching scenarios.
Tuning and response
Baseline known deployment tools, approved targets and change windows together. Avoid permanent allowlists based only on a filename, signer or administrator account. Review exceptions periodically and retain visibility into changed targets and unusual arguments. Hunt across the fleet for the artifact hash, resolved target, command line and writer pattern, while accounting for renamed files.
If evidence indicates unauthorized persistence, follow the incident-response playbook for isolation and removal. Preserve artifacts and volatile evidence as appropriate before remediation; do not reboot merely to test execution. Coordinate business impact with the owner, investigate the initial entry point, and verify that persistence does not return. Document affected users and devices, time range, evidence, confidence, collection gaps, response actions and validation.
Key takeaways
- Separate a Startup-folder change from execution and impact.
- Resolve shortcuts safely and investigate both the writer and target.
- Validate log coverage and query field mappings before drawing conclusions.
- Use narrow, reviewable tuning and preserve evidence before containment.
Continue with our Registry Run-Key investigation guide to compare another logon persistence mechanism.
EmoticonEmoticon