{"id":"T1546.004","name":"Unix Shell Configuration Modification","url":"https://attack.mitre.org/techniques/T1546/004","tactics":["privilege-escalation","persistence"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0020","stix_id":"x-mitre-detection-strategy--f09870f8-77d4-4b58-8bda-2b3f2e29c897","name":"Detect Shell Configuration Modification for Persistence via Event-Triggered Execution","url":"https://attack.mitre.org/detectionstrategies/DET0020","analytics":[{"id":"AN0059","stix_id":"x-mitre-analytic--3ae99176-ce61-4598-834b-f48d13802dcb","name":"Analytic 0059","description":"Detects modification of shell startup/logout scripts such as ~/.bashrc, ~/.bash_profile, or /etc/profile, followed by anomalous process execution or network connections upon interactive or remote shell login.","url":"https://attack.mitre.org/detectionstrategies/DET0020#AN0059","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"AUDIT_SYSCALL (open, write, rename, unlink)","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"execution of unexpected binaries during user shell startup","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"NSM:Flow","channel":"unexpected network activity initiated shortly after shell session starts","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines how soon after shell startup process execution or network activity is considered suspicious."},{"field":"TargetUser","description":"Limits detection to specific user accounts or roles such as root or service accounts."},{"field":"FilePathRegex","description":"Defines what shell configuration paths are considered relevant (e.g., .bashrc, .bash_logout, etc.)"}],"live":true,"detection_strategies":["DET0020"],"techniques":["T1546.004"]},{"id":"AN0060","stix_id":"x-mitre-analytic--6acf01f9-723e-499b-8774-3fa689a36ded","name":"Analytic 0060","description":"Correlates zsh shell configuration file changes (e.g., ~/.zshrc, ~/.zlogin, /etc/zprofile) with execution of unauthorized binaries or unexpected network activity triggered on Terminal.app launch.","url":"https://attack.mitre.org/detectionstrategies/DET0020#AN0060","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"launch of Terminal.app or shell with non-standard environment setup","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_WRITE, targeting .zshrc, .zlogin, .zprofile","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"FileTargetList","description":"Customizable list of shell config files considered sensitive for detection."},{"field":"PayloadEntropyThreshold","description":"Used to distinguish benign from potentially obfuscated commands written to config files."},{"field":"UserContext","description":"Scoping based on user login class, e.g., administrative vs standard users."}],"live":true,"detection_strategies":["DET0020"],"techniques":["T1546.004"]}],"live":true,"version":"1.0","techniques":["T1546.004"]}],"sigma_rules":[{"id":"a94cdd87-6c54-4678-a6cc-2814ffe5a13d","title":"Unix Shell Configuration Modification","author":"Peter Matkovski, IAI","status":"test","level":"medium","date":"2023-03-06","modified":"2023-03-15","description":"Detect unix shell configuration modification. Adversaries may establish persistence through executing malicious commands triggered when a new shell is opened.","references":["https://objective-see.org/blog/blog_0x68.html","https://web.archive.org/web/20221204161143/https://www.glitch-cat.com/p/green-lambert-and-attack","https://www.anomali.com/blog/pulling-linux-rabbit-rabbot-malware-out-of-a-hat"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.004"],"path":"rules/linux/auditd/path/lnx_auditd_unix_shell_configuration_modification.yml","techniques":["T1546.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}