{"id":"T1546","name":"Event Triggered Execution","url":"https://attack.mitre.org/techniques/T1546","tactics":["privilege-escalation","persistence"],"platforms":["Linux","macOS","Windows","SaaS","IaaS","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0010","stix_id":"x-mitre-detection-strategy--c5e3823f-5ee0-43db-b6fa-b63d6587b24c","name":"Behavioral Detection of Event Triggered Execution Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0010","analytics":[{"id":"AN0024","stix_id":"x-mitre-analytic--9418d7e2-666f-4f73-9ac7-96b32005e9b7","name":"Analytic 0024","description":"Correlates unexpected modifications to WMI event filters, scheduled task triggers, or registry autorun keys with subsequent execution of non-standard binaries by SYSTEM-level processes.","url":"https://attack.mitre.org/detectionstrategies/DET0010#AN0024","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4698","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:WMI","channel":"Creation or modification of __EventFilter, __FilterToConsumerBinding, or CommandLineEventConsumer","data_component":"DC0008","data_component_name":"WMI Creation","log_source_slug":"wineventlog-wmi"},{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"UserContext","description":"Filters triggering on SYSTEM or LOCAL SERVICE vs. user-initiated triggers"},{"field":"TimeWindow","description":"Correlates trigger definition and execution timing (e.g., within 5 minutes)"},{"field":"PathAnomalyThreshold","description":"Process or binary path deviation scoring for execution anomalies"}],"live":true,"detection_strategies":["DET0010"],"techniques":["T1546"]},{"id":"AN0025","stix_id":"x-mitre-analytic--92d182e9-6723-43e4-9eab-f00aa6d53153","name":"Analytic 0025","description":"Detects inotify or auditd configuration changes that monitor system files coupled with execution of script interpreters or binaries by cron or systemd timers.","url":"https://attack.mitre.org/detectionstrategies/DET0010#AN0025","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"Inotify watch creation or auditctl changes on /etc/cron* or /lib/systemd/system/","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Execution of non-standard script or binary by cron","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"linux-syslog"},{"name":"auditd:SYSCALL","channel":"Execution of script interpreters by systemd timer (ExecStart)","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"ExecutablePathRegex","description":"Regex defining suspicious binary/script paths triggered by cron/systemd"},{"field":"WatchTargetPaths","description":"Paths monitored by auditd/inotify for suspicious event registration"}],"live":true,"detection_strategies":["DET0010"],"techniques":["T1546"]},{"id":"AN0026","stix_id":"x-mitre-analytic--636b1cca-1fc4-4909-ac33-c2b2a7d69e02","name":"Analytic 0026","description":"Correlates launchd plist modifications with subsequent unauthorized script execution or anomalous parent-child process trees involving user agents.","url":"https://attack.mitre.org/detectionstrategies/DET0010#AN0026","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Modification of ~/Library/LaunchAgents or /Library/LaunchDaemons plist","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Execution of launchctl with suspicious arguments","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"PlistNamePattern","description":"Regex pattern matching known rogue or unrecognized launchd plist names"},{"field":"ParentProcessBaseline","description":"Expected parent-child relationships during plist-triggered execution"}],"live":true,"detection_strategies":["DET0010"],"techniques":["T1546"]},{"id":"AN0027","stix_id":"x-mitre-analytic--0fb1d87b-e993-447e-8a2f-e9d42f6859c0","name":"Analytic 0027","description":"Monitors cloud function creation triggered by specific audit log events (e.g., IAM changes, object creation), followed by anomalous behavior from new service accounts.","url":"https://attack.mitre.org/detectionstrategies/DET0010#AN0027","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"CreateFunction","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"InvokeFunction","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"TriggerEventType","description":"Specific cloud event (e.g., PutObject, CreateRole) that causes function invocation"},{"field":"ServiceAccountRole","description":"Expected permissions for roles used in function execution"}],"live":true,"detection_strategies":["DET0010"],"techniques":["T1546"]},{"id":"AN0028","stix_id":"x-mitre-analytic--982100e1-6d38-4d0e-b36d-7e2d2cf5a424","name":"Analytic 0028","description":"Correlates Power Automate or similar logic app workflows triggered by SaaS file uploads or email rules with data forwarding or anomalous access patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0010#AN0028","platforms":["SaaS"],"log_source_references":[{"name":"m365:unified","channel":"Creation of Power Automate flow triggered by OneDrive or Exchange event","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"m365-unified"},{"name":"m365:unified","channel":"Automated forwarding or file sync initiated by a logic app","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"TriggerCondition","description":"Event types that initiate SaaS automation (e.g., file add, new email)"},{"field":"AppIdentityScope","description":"Scopes/permissions granted to automation app accounts"}],"live":true,"detection_strategies":["DET0010"],"techniques":["T1546"]},{"id":"AN0029","stix_id":"x-mitre-analytic--d8e18081-2670-4a88-9246-59a1dc52c51c","name":"Analytic 0029","description":"Detects macros or VBA triggers set to execute on document open or close events, often correlating with embedded payloads or C2 traffic shortly after execution.","url":"https://attack.mitre.org/detectionstrategies/DET0010#AN0029","platforms":["Office Suite"],"log_source_references":[{"name":"m365:office","channel":"VBA auto_open, auto_close, or document_open events","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"m365-office"},{"name":"m365:office","channel":"External HTTP/DNS connection from Office binary shortly after macro trigger","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"m365-office"}],"mutable_elements":[{"field":"MacroFunctionNames","description":"Names of event-bound functions like Auto_Open that initiate execution"},{"field":"TimeDeltaMacroToC2","description":"Time threshold to correlate macro execution with outbound connections"}],"live":true,"detection_strategies":["DET0010"],"techniques":["T1546"]}],"live":true,"version":"1.0","techniques":["T1546"]}],"sigma_rules":[{"id":"07743f65-7ec9-404a-a519-913db7118a8d","title":"COM Hijack via Sdclt","author":"Omkar Gudhate","status":"test","level":"high","date":"2020-09-27","modified":"2023-09-28","description":"Detects changes to 'HKCU\\Software\\Classes\\Folder\\shell\\open\\command\\DelegateExecute'","references":["http://blog.sevagas.com/?Yet-another-sdclt-UAC-bypass","https://www.exploit-db.com/exploits/47696"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546","attack.t1548"],"path":"rules/windows/registry/registry_set/registry_set_comhijack_sdclt.yml","techniques":["T1546","T1548"],"cves":[]},{"id":"0ba863e6-def5-4e50-9cea-4dd8c7dc46a4","title":"Control Panel Items","author":"Kyaw Min Thein, Furkan Caliskan (@caliskanfurkan_)","status":"test","level":"high","date":"2020-06-22","modified":"2023-10-11","description":"Detects the malicious use of a control panel item","references":["https://ired.team/offensive-security/code-execution/code-execution-through-control-panel-add-ins"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.stealth","attack.t1218.002","attack.persistence","attack.t1546"],"path":"rules/windows/process_creation/proc_creation_win_control_panel_item.yml","techniques":["T1218.002","T1546"],"cves":[]},{"id":"0c3fac91-5627-46e8-a6a8-a0d7b9b8ae1b","title":"Suspicious Get-Variable.exe Creation","author":"frack113","status":"test","level":"high","date":"2022-04-23","modified":null,"description":"Get-Variable is a valid PowerShell cmdlet\nWindowsApps is by default in the path where PowerShell is executed.\nSo when the Get-Variable command is issued on PowerShell execution, the system first looks for the Get-Variable executable in the path and executes the malicious binary instead of looking for the PowerShell cmdlet.\n","references":["https://blog.malwarebytes.com/threat-intelligence/2022/04/colibri-loader-combines-task-scheduler-and-powershell-in-clever-persistence-technique/","https://www.joesandbox.com/analysis/465533/0/html"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.stealth","attack.t1546","attack.t1027"],"path":"rules/windows/file/file_event/file_event_win_susp_get_variable.yml","techniques":["T1546","T1027"],"cves":[]},{"id":"117d3d3a-755c-4a61-b23e-9171146d094c","title":"Suspicious Outlook Macro Created","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-02-08","modified":null,"description":"Detects the creation of a macro file for Outlook.","references":["https://www.mdsec.co.uk/2020/11/a-fresh-outlook-on-mail-based-persistence/","https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=53","https://www.linkedin.com/pulse/outlook-backdoor-using-vba-samir-b-/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.command-and-control","attack.t1137","attack.t1008","attack.t1546"],"path":"rules/windows/file/file_event/file_event_win_office_outlook_susp_macro_creation.yml","techniques":["T1137","T1008","T1546"],"cves":[]},{"id":"396ae3eb-4174-4b9b-880e-dc0364d78a19","title":"Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-04-05","modified":"2023-08-17","description":"Detects the modification of Outlook setting \"LoadMacroProviderOnBoot\" which if enabled allows the automatic loading of any configured VBA project/module","references":["https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=53","https://www.linkedin.com/pulse/outlook-backdoor-using-vba-samir-b-/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.command-and-control","attack.t1137","attack.t1008","attack.t1546"],"path":"rules/windows/registry/registry_set/registry_set_office_outlook_enable_load_macro_provider_on_boot.yml","techniques":["T1137","T1008","T1546"],"cves":[]},{"id":"711ab2fe-c9ba-4746-8840-5228a58c3cb8","title":"MSSQL Extended Stored Procedure Backdoor Maggie","author":"Denis Szadkowski, DIRT / DCSO CyTec","status":"test","level":"high","date":"2022-10-09","modified":null,"description":"This rule detects the execution of the extended storage procedure backdoor named Maggie in the context of Microsoft SQL server","references":["https://medium.com/@DCSO_CyTec/mssql-meet-maggie-898773df3b01"],"logsource":{"product":"windows","service":"application"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546","detection.emerging-threats"],"path":"rules-emerging-threats/2022/Malware/win_mssql_sp_maggie.yml","techniques":["T1546"],"cves":[]},{"id":"7ba08e95-1e0b-40cd-9db5-b980555e42fd","title":"SOURGUM Actor Behaviours","author":"MSTIC, FPT.EagleEye","status":"test","level":"high","date":"2021-06-15","modified":"2022-10-09","description":"Suspicious behaviours related to an actor tracked by Microsoft as SOURGUM","references":["https://www.virustotal.com/gui/file/c299063e3eae8ddc15839767e83b9808fd43418dc5a1af7e4f44b97ba53fbd3d/detection","https://github.com/Azure/Azure-Sentinel/blob/43e9be273dca321295190bfc4902858e009d4a35/Detections/MultipleDataSources/SOURGUM_IOC.yaml","https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1546","attack.t1546.015","attack.persistence","attack.privilege-escalation","detection.emerging-threats"],"path":"rules-emerging-threats/2021/TA/SOURGUM/proc_creation_win_apt_sourgrum.yml","techniques":["T1546","T1546.015"],"cves":[]},{"id":"8c31f563-f9a7-450c-bfa8-35f8f32f1f61","title":"New Outlook Macro Created","author":"@ScoubiMtl","status":"test","level":"medium","date":"2021-04-05","modified":"2023-02-08","description":"Detects the creation of a macro file for Outlook.","references":["https://www.mdsec.co.uk/2020/11/a-fresh-outlook-on-mail-based-persistence/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.command-and-control","attack.t1137","attack.t1008","attack.t1546"],"path":"rules/windows/file/file_event/file_event_win_office_outlook_macro_creation.yml","techniques":["T1137","T1008","T1546"],"cves":[]},{"id":"bbb2dedd-a0e3-46ab-ba6c-6c82ae7a9aa7","title":"HAFNIUM Exchange Exploitation Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-03-09","modified":"2023-03-09","description":"Detects activity observed by different researchers to be HAFNIUM group activity (or related) on Exchange servers","references":["https://blog.truesec.com/2021/03/07/exchange-zero-day-proxylogon-and-hafnium/","https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/","https://discuss.elastic.co/t/detection-and-response-for-hafnium-activity/266289/3","https://twitter.com/GadixCRK/status/1369313704869834753?s=20","https://twitter.com/BleepinComputer/status/1372218235949617161"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.t1546","attack.t1053","attack.g0125","detection.emerging-threats"],"path":"rules-emerging-threats/2021/TA/HAFNIUM/proc_creation_win_apt_hafnium.yml","techniques":["T1546","T1053"],"cves":[]},{"id":"e3b50fa5-3c3f-444e-937b-0a99d33731cd","title":"Outlook Macro Execution Without Warning Setting Enabled","author":"@ScoubiMtl","status":"test","level":"high","date":"2021-04-05","modified":"2023-08-17","description":"Detects the modification of Outlook security setting to allow unprompted execution of macros.","references":["https://www.mdsec.co.uk/2020/11/a-fresh-outlook-on-mail-based-persistence/","https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=53"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.persistence","attack.command-and-control","attack.t1137","attack.t1008","attack.t1546"],"path":"rules/windows/registry/registry_set/registry_set_office_outlook_enable_macro_execution.yml","techniques":["T1137","T1008","T1546"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}