Install WanaCry persistence via registry

WannaCry uses the Windows registry Run key for persistence. This technique stages and writes a PneumaEX agent to disk and configures the Run key to start it.
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.


Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
APT38 WannaCry


Perform lateral movement using EternalBlue and DoublePulsar exploits.