{"id":"T1037","name":"Boot or Logon Initialization Scripts","url":"https://attack.mitre.org/techniques/T1037","tactics":["persistence","privilege-escalation"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0112","stix_id":"x-mitre-detection-strategy--6928b108-f04e-4a9b-bda5-53bb0c64ec9b","name":"Boot or Logon Initialization Scripts Detection Strategy","url":"https://attack.mitre.org/detectionstrategies/DET0112","analytics":[{"id":"AN0311","stix_id":"x-mitre-analytic--682bd971-c540-4c16-a25a-b928201a320d","name":"Analytic 0311","description":"Monitoring modification and execution of user or system logon scripts such as in registry Run keys or startup folders.","url":"https://attack.mitre.org/detectionstrategies/DET0112#AN0311","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:TaskScheduler","channel":"EventCode=106","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"wineventlog-taskscheduler"}],"mutable_elements":[{"field":"TargetObject","description":"Registry path that may vary by user or policy configuration."},{"field":"ParentProcessName","description":"Can be tuned to known parent processes to reduce false positives."},{"field":"TimeWindow","description":"Logon activity clustered during specific user shifts."}],"live":true,"detection_strategies":["DET0112"],"techniques":["T1037"]},{"id":"AN0312","stix_id":"x-mitre-analytic--0f8a0af6-7544-4f29-8e08-6b07dda1337e","name":"Analytic 0312","description":"Detection of changes or execution of shell initialization scripts like .bashrc, .profile, or /etc/profile for persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0112#AN0312","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"EXECVE","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:PATH","channel":"PATH","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"auditd-path"},{"name":"linux:osquery","channel":"file_events","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"FilePath","description":"Initialization script path that can differ across user and system profiles."},{"field":"UserContext","description":"User-level vs root-level configuration."},{"field":"TimeWindow","description":"Useful to correlate between file change and subsequent execution."}],"live":true,"detection_strategies":["DET0112"],"techniques":["T1037"]},{"id":"AN0313","stix_id":"x-mitre-analytic--3b218f49-59ce-44a5-a10b-889c99e78934","name":"Analytic 0313","description":"Monitoring for modification and execution of login hook scripts or LaunchAgents/LaunchDaemons used for persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0112#AN0313","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"file","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"fs-fsusage"},{"name":"macos:osquery","channel":"launchd","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"Label","description":"LaunchAgent or LaunchDaemon label name, often environment-specific."},{"field":"ProgramArguments","description":"Arguments passed to scripts, which may need tuning by environment."},{"field":"UserContext","description":"Distinguish between user login and system startup agents."}],"live":true,"detection_strategies":["DET0112"],"techniques":["T1037"]},{"id":"AN0314","stix_id":"x-mitre-analytic--32199f21-430f-4c91-b2d7-a0b7409cd5f0","name":"Analytic 0314","description":"Detection of modification to ESXi rc.local.d or rc scripts that are used to execute on boot.","url":"https://attack.mitre.org/detectionstrategies/DET0112#AN0314","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"boot","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"esxi-vmkernel"},{"name":"esxi:hostd","channel":"boot","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"ScriptName","description":"Script path or name may vary across hypervisor versions."},{"field":"LogSeverity","description":"Log verbosity settings may alter visibility of activity."}],"live":true,"detection_strategies":["DET0112"],"techniques":["T1037"]},{"id":"AN0315","stix_id":"x-mitre-analytic--416b5616-a16d-4ccc-b214-5873f96e5b1f","name":"Analytic 0315","description":"Detection of changes to device startup-config files that include boot scripts or scheduled execution routines.","url":"https://attack.mitre.org/detectionstrategies/DET0112#AN0315","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"config","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"Interface","description":"Affected interface or subsystem; varies per device."},{"field":"CommandPattern","description":"Patterns of authorized config changes differ by vendor or policy."}],"live":true,"detection_strategies":["DET0112"],"techniques":["T1037"]}],"live":true,"version":"1.0","techniques":["T1037"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2024-20359","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-20353","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-41328","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}