Sub-technique of T1037 Boot or Logon Initialization Scripts.View on attack.mitre.org
Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence. Windows allows logon scripts to be run whenever a specific user or group of users log into a system. This is done via adding a path to a script to the HKCU\Environment\UserInitMprLogonScript Registry key.
Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.
Rules on DetectionCode tagged with T1037.001.
| Rule | Level | Log source |
|---|---|---|
| Potential Persistence Via Logon Scripts - CommandLine | high | windows / process_creation |
| Uncommon Userinit Child Process | high | windows / process_creation |
| Potential Persistence Via Logon Scripts - Registry | medium | windows / registry_set |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Logon Script Event Trigger Execution | TTP | NULL | Sysmon EventID 13 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT28 | An APT28 loader Trojan adds the Registry key |
| GroupCobalt Group | Cobalt Group has added persistence by registering the file name for the next stage malware under |
| Used by | Procedure example |
|---|---|
| MalwareAttor | Attor's dispatcher can establish persistence via adding a Registry key with a logon script |
| MalwareJHUHUGIT | JHUHUGIT has registered a Windows shell script under the Registry key |
| MalwareKGH_SPY | KGH_SPY has the ability to set the |
| MalwareZebrocy | Zebrocy performs persistence with a logon script via adding to the Registry key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.