WannaCry uses the Windows registry Run key for persistence. This technique stages and writes a PneumaEX agent to disk and configures the Run key to start it.
View Command
To view this TTPs command, you must be logged in with a professional or enterprise license.