~/Privilege Escalation/Windows/Binaries# cat Runonce.exe.md

Paths:

C:\Windows\System32\runonce.exe
C:\Windows\SysWOW64\runonce.exe

Detection: HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\YOURKEY

Execute

Executes a Run Once Task that has been configured in the registry

Runonce.exe /AlternateShellStartup