Technique with 18 sub-techniques.View on attack.mitre.org
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cloud environments may also support various functions and services that monitor and can be invoked in response to specific cloud events.
Adversaries may abuse these mechanisms as a means of maintaining persistent access to a victim via repeatedly executing malicious code. After gaining access to a victim system, adversaries may create/modify event triggers to point to malicious content that will be executed whenever the event trigger is invoked.
Since the execution can be proxied by an account with higher permissions, such as SYSTEM or service accounts, an adversary may be able to abuse these triggered execution mechanisms to escalate their privileges.
Rules on DetectionCode tagged with T1546 or one of its sub-techniques.
| ID | Name | Examples |
|---|---|---|
| T1546.001 | Change Default File Association | 2 |
| T1546.002 | Screensaver | 1 |
| T1546.003 | Windows Management Instrumentation Event Subscription | 25 |
| T1546.004 | Unix Shell Configuration Modification | 7 |
| T1546.005 | Trap | 0 |
| T1546.006 | LC_LOAD_DYLIB Addition | 0 |
| T1546.007 | Netsh Helper DLL | 1 |
| T1546.008 | Accessibility Features | 7 |
| T1546.009 | AppCert DLLs | 1 |
| T1546.010 | AppInit DLLs | 4 |
| T1546.011 | Application Shimming | 4 |
| T1546.012 | Image File Execution Options Injection | 3 |
| T1546.013 | PowerShell Profile | 1 |
| T1546.014 | Emond | 0 |
| T1546.015 | Component Object Model Hijacking | 12 |
| T1546.016 | Installer Packages | 5 |
| T1546.017 | Udev Rules | 1 |
| T1546.018 | Python Startup Hooks | 2 |
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareMini Shai-Hulud | Mini Shai-Hulud has modified settings and configuration files of AI coding agents and other coding applications in order to create event triggered executions through creating hooks and runOn conditions. |
| ToolPacu | Pacu can set up S3 bucket notifications to trigger a malicious Lambda function when a CloudFormation template is uploaded to the bucket. It can also create Lambda functions that trigger upon the creation of users, roles, and groups. |
| MalwareUPSTYLE | UPSTYLE creates a `.pth` file beginning with the text `import` so that any time another process or script attempts to reference the modified item the malicious code will also run. |
| MalwareXCSSET | XCSSET's `dfhsebxzod` module searches for `.xcodeproj` directories within the user’s home folder and subdirectories. For each match, it locates the corresponding `project.pbxproj` file and embeds an encoded payload into a build rule, target configuration, or project setting. The payload is later executed during the build process. |
| Used by | Procedure example |
|---|---|
| CampaignKV Botnet Activity | KV Botnet Activity involves managing events on victim systems via |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.