TGViewer
Sec Note Sec Note @secnote · 2.89K subscribers
Post #245 3.07K
Registry Writes Without Registry Callbacks

The Bypass
Placing a crafted NTUSER.MAN in C:\Users\<target>\ loads persistence keys into HKCU on next logon. The hive is loaded directly from disk without invoking registry APIs.

CmRegisterCallbackEx monitors registry operations. Hive loads are not registry operations. The callbacks are not invoked.

Filesystem events will trigger. Writing the file to the profile directory is visible to any EDR monitoring file operations. Registry-focused detections remain blind.


#EDR #Persistence
  • 👾 7
More from @secnote
  1. Sep 27, 2026EDR Evasion: Process Injection Without WriteProcessMemory #EDR #maldev
  2. Sep 25, 2026سلام و درود لنگ ظهر جمعه تون بخیر فایل 4 دوره #SEC530 خدمت شما. واقعا طولانی شد 😅
  3. Sep 24, 2026Sec Note pinned a photo
  4. Sep 24, 2026My New Blog Post Evading Sysmon Dns Monitoring In 2026 | binary-win DNSevade : https://git…
  5. Sep 23, 2026Did Sysmon miss the DNS event?👀
  6. Sep 22, 2026fbi job portal defaced and compromised? oh yeah, it's a silly tuesday
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →