Technique with 5 sub-techniques.View on attack.mitre.org
Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts can be used to perform administrative functions, which may often execute other programs or send information to an internal logging server. These scripts can vary based on operating system and whether applied locally or remotely.
Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.
An adversary may also be able to escalate their privileges since some boot or logon initialization scripts run with higher privileges.
Rules on DetectionCode tagged with T1037 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Potential Persistence Via Logon Scripts - CommandLine | high | windows / process_creation | T1037.001 |
| Uncommon Userinit Child Process | high | windows / process_creation | T1037.001 |
| Potential Persistence Via Logon Scripts - Registry | medium | windows / registry_set | T1037.001 |
| Startup Item File Created - MacOS | low | macos / file_event | T1037.005 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Linux File Creation In Init Boot Directory | Anomaly | NULL | Sysmon for Linux EventID 11 | T1037.004 |
| Linux File Creation In System Generator Directory | Anomaly | NULL | Sysmon for Linux EventID 11 | T1037.005 |
| Linux MOTD Script Added | Anomaly | NULL | Sysmon for Linux EventID 11 | T1037 |
| Linux Suspicious XDG Autostart | Anomaly | NULL | Sysmon for Linux EventID 11 | T1037 |
| Linux UDEV Rule Created | Anomaly | NULL | Sysmon for Linux EventID 11 | T1037 |
| Logon Script Event Trigger Execution | TTP | NULL | Sysmon EventID 13 | T1037.001 |
| MacOS LoginHook Persistence | TTP | NULL | Osquery Results | T1037.002 |
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup. |
| GroupAPT41 | APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit. |
| GroupRocke | Rocke has installed an "init.d" startup script to maintain persistence. |
| GroupUNC3886 | UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices. |
| Used by | Procedure example |
|---|---|
| MalwareRotaJakiro | Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.conf` file in the `/etc/init/` folder. |
| MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence. |
| MalwareVIRTUALPITA | VIRTUALPITA can persist as an init.d startup service on Linux vCenter systems. |
| Used by | Procedure example |
|---|---|
| CampaignArcaneDoor | ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.