Not really… It’s just editing (manually or with proper script) a Windows Registry key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\BootExecute