{"id":"T1547","name":"Boot or Logon Autostart Execution","url":"https://attack.mitre.org/techniques/T1547","tactics":["persistence","privilege-escalation"],"platforms":["Linux","macOS","Windows","Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0274","stix_id":"x-mitre-detection-strategy--a9796458-df5d-467f-b037-acad6c261f25","name":"Boot or Logon Autostart Execution Detection Strategy","url":"https://attack.mitre.org/detectionstrategies/DET0274","analytics":[{"id":"AN0764","stix_id":"x-mitre-analytic--aa12f037-f724-43a6-97ca-e2e706859c1a","name":"Analytic 0764","description":"Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup","url":"https://attack.mitre.org/detectionstrategies/DET0274#AN0764","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ParentProcessName","description":"Customize based on expected parent-child process lineage for autostarts"},{"field":"StartupRegistryPath","description":"May vary based on organization policy or installed software"}],"live":true,"detection_strategies":["DET0274"],"techniques":["T1547"]},{"id":"AN0765","stix_id":"x-mitre-analytic--156387d6-9b9a-49f8-834a-cf3cd5ede09c","name":"Analytic 0765","description":"Correlates creation/modification of systemd service files or /etc/init.d scripts with outlier process behavior during boot","url":"https://attack.mitre.org/detectionstrategies/DET0274#AN0765","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"creat","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"Execution of binaries located in /etc/init.d/ or systemd service paths","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"FilePath","description":"Organizations may use different init systems or custom startup paths"},{"field":"UserContext","description":"Autostart scripts should run as root or system users; deviations are suspect"}],"live":true,"detection_strategies":["DET0274"],"techniques":["T1547"]},{"id":"AN0766","stix_id":"x-mitre-analytic--eb0d78b0-f35d-49db-a8a5-d3cf840db6fd","name":"Analytic 0766","description":"Observes creation or modification of LaunchAgent/LaunchDaemon property list files combined with anomalous plist payload execution after user logon","url":"https://attack.mitre.org/detectionstrategies/DET0274#AN0766","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Observed loading of new LaunchAgent or LaunchDaemon plist","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Execution of binary listed in newly modified LaunchAgent plist","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"PlistKey","description":"Organizations may use specific keys or additional payload parameters"},{"field":"TimeWindow","description":"Tunable based on expected delay between plist write and execution"}],"live":true,"detection_strategies":["DET0274"],"techniques":["T1547"]}],"live":true,"version":"1.0","techniques":["T1547"]}],"sigma_rules":[{"id":"123e4e6d-b123-48f8-b261-7214938acaf0","title":"Startup/Logon Script Added to Group Policy Object","author":"Elastic, Josh Nickels, Marius Rothenbücher","status":"test","level":"medium","date":"2024-09-06","modified":null,"description":"Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.\n","references":["https://www.elastic.co/guide/en/security/current/startup-logon-script-added-to-group-policy-object.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.privilege-escalation","attack.defense-impairment","attack.t1484.001","attack.t1547"],"path":"rules/windows/builtin/security/win_security_susp_group_policy_startup_script_added_to_gpo.yml","techniques":["T1484.001","T1547"],"cves":[]},{"id":"277efb8f-60be-4f10-b4d3-037802f37167","title":"Registry Persistence Mechanisms in Recycle Bin","author":"frack113","status":"test","level":"high","date":"2021-11-18","modified":"2022-12-06","description":"Detects persistence registry keys for Recycle Bin","references":["https://github.com/vxunderground/VXUG-Papers/blob/751edb8d50f95bd7baa730adf2c6c3bb1b034276/The%20Persistence%20Series/Persistence%20via%20Recycle%20Bin/Persistence_via_Recycle_Bin.pdf","https://persistence-info.github.io/Data/recyclebin.html","https://www.hexacorn.com/blog/2018/05/28/beyond-good-ol-run-key-part-78-2/"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547"],"path":"rules/windows/registry/registry_event/registry_event_persistence_recycle_bin.yml","techniques":["T1547"],"cves":[]},{"id":"9577edbb-851f-4243-8c91-1d5b50c1a39b","title":"Atbroker Registry Change","author":"Mateusz Wydra, oscd.community","status":"test","level":"medium","date":"2020-10-13","modified":"2023-01-19","description":"Detects creation/modification of Assistive Technology applications and persistence with usage of 'at'","references":["http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/","https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1218","attack.persistence","attack.t1547"],"path":"rules/windows/registry/registry_event/registry_event_susp_atbroker_change.yml","techniques":["T1218","T1547"],"cves":[]},{"id":"a2ea3ae7-d3d0-40a0-a55c-25a45c87cac1","title":"Suspicious Driver Install by pnputil.exe","author":"Hai Vaknin @LuxNoBulIshit, Avihay eldad  @aloneliassaf, Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-09-30","modified":"2022-10-09","description":"Detects when a possible suspicious driver is being installed via pnputil.exe lolbin","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/pnputil-command-syntax","https://strontic.github.io/xcyclopedia/library/pnputil.exe-60EDC5E6BDBAEE441F2E3AEACD0340D2.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml","techniques":["T1547"],"cves":[]},{"id":"a6976974-ea6f-4e97-818e-ea08625c52cb","title":"Potential RipZip Attack on Startup Folder","author":"Greg (rule)","status":"test","level":"high","date":"2022-07-21","modified":"2023-01-05","description":"Detects a phishing attack which expands a ZIP file containing a malicious shortcut.\nIf the victim expands the ZIP file via the explorer process, then the explorer process expands the malicious ZIP file and drops a malicious shortcut redirected to a backdoor into the Startup folder.\nAdditionally, the file name of the malicious shortcut in Startup folder contains {0AFACED1-E828-11D1-9187-B532F1E9575D} meaning the folder shortcut operation.\n","references":["https://twitter.com/jonasLyk/status/1549338335243534336?t=CrmPocBGLbDyE4p6zTX1cg&s=19"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547"],"path":"rules/windows/file/file_event/file_event_win_ripzip_attack.yml","techniques":["T1547"],"cves":[]},{"id":"b98968aa-dbc0-4a9c-ac35-108363cbf8d5","title":"WINEKEY Registry Modification","author":"omkar72","status":"test","level":"high","date":"2020-10-30","modified":"2021-11-27","description":"Detects potential malicious modification of run keys by winekey or team9 backdoor","references":["https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547"],"path":"rules/windows/registry/registry_event/registry_event_runkey_winekey.yml","techniques":["T1547"],"cves":[]},{"id":"f14e169e-9978-4c69-acb3-1cff8200bc36","title":"Suspicious GrpConv Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-05-19","modified":null,"description":"Detects the suspicious execution of a utility to convert Windows 3.x .grp files or for persistence purposes by malicious software or actors","references":["https://twitter.com/0gtweet/status/1526833181831200770"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1547"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_susp_grpconv.yml","techniques":["T1547"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-2533","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}