Startup Items

T1037.005

Sub-technique of T1037 Boot or Logon Initialization Scripts.View on attack.mitre.org

About this technique

Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items.

This is technically a deprecated technology (superseded by Launch Daemon), and thus the appropriate folder, /Library/StartupItems isn’t guaranteed to exist on the system by default, but does appear to exist by default on macOS Sierra. A startup item is a directory whose executable and configuration property list (plist), StartupParameters.plist, reside in the top-level directory.

An adversary can create the appropriate folders/files in the StartupItems directory to register their own persistence mechanism. Additionally, since StartupItems run during the bootup phase of macOS, they will run as the elevated root user.

Detection rules2

Rules on DetectionCode tagged with T1037.005.

Sigma1

RuleLevelLog source
Startup Item File Created - MacOSlowmacos / file_event

Splunk1

RuleTypeRiskData source
Linux File Creation In System Generator DirectoryAnomalyNULLSysmon for Linux EventID 11

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwarejRAT

jRAT can list and manage startup entries.

References2

  1. Methods of Mac Malware Persistence Open source
    Patrick Wardle. (2014, September). Methods of Malware Persistence on Mac OS X. Retrieved July 5, 2017.
  2. Startup Items Open source
    Apple. (2016, September 13). Startup Items. Retrieved July 11, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.