Event Triggered Execution

T1546

Technique with 18 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cloud environments may also support various functions and services that monitor and can be invoked in response to specific cloud events.

Adversaries may abuse these mechanisms as a means of maintaining persistent access to a victim via repeatedly executing malicious code. After gaining access to a victim system, adversaries may create/modify event triggers to point to malicious content that will be executed whenever the event trigger is invoked.

Since the execution can be proxied by an account with higher permissions, such as SYSTEM or service accounts, an adversary may be able to abuse these triggered execution mechanisms to escalate their privileges.

Detection rules88

Rules on DetectionCode tagged with T1546 or one of its sub-techniques.

Sigma60

RuleLevelLog sourceTechnique
Persistence Via Sticky Key Backdoorcriticalwindows / process_creationT1546.008
Sticky Key Like Backdoor Executioncriticalwindows / process_creationT1546.008
Sticky Key Like Backdoor Usage - Registrycriticalwindows / registry_eventT1546.008
WMI Backdoor Exchange Transport Agentcriticalwindows / process_creationT1546.003
Change Default File Association To Executable Via Assochighwindows / process_creationT1546.001
COM Hijack via Sdclthighwindows / registry_setT1546
COM Object Hijacking Via Modification Of Default System CLSID Default Valuehighwindows / registry_setT1546.015
Control Panel Itemshighwindows / process_creationT1546
New Netsh Helper DLL Registered From A Suspicious Locationhighwindows / registry_setT1546.007
NewActiveScriptEventConsumer Creation Attempt via Wmic.EXEhighwindows / process_creationT1546.003
Outlook Macro Execution Without Warning Setting Enabledhighwindows / registry_setT1546
Potential Persistence Via App Paths Default Propertyhighwindows / registry_setT1546.012
Potential Persistence Via GlobalFlagshighwindows / registry_setT1546.012
Potential Persistence Via Outlook LoadMacroProviderOnBoot Settinghighwindows / registry_setT1546
Potential Persistence Via Shim Database In Uncommon Locationhighwindows / registry_setT1546.011

Splunk28

RuleTypeRiskData sourceTechnique
Change Default File AssociationTTPNULLSysmon EventID 12, Sysmon EventID 13T1546.001
Detect WMI Event Subscription PersistenceTTPNULLSysmon EventID 20T1546.003
Linux Auditd Unix Shell Configuration ModificationTTPNULLLinux Auditd Path, Linux Auditd CwdT1546.004
Linux File Creation In Profile DirectoryAnomalyNULLSysmon for Linux EventID 11T1546.004
Linux Possible Append Command To Profile Config FileAnomalyNULLSysmon for Linux EventID 1T1546.004
Overwriting Accessibility BinariesTTPNULLSysmon EventID 11T1546.008
Powershell COM Hijacking InprocServer32 ModificationTTPNULLPowershell Script Block Logging 4104T1546.015
Powershell Execute COM ObjectTTPNULLPowershell Script Block Logging 4104T1546.015
Python PTH File Creation During Package InstallationAnomalyNULLSysmon EventID 1 AND Sysmon EventID 11T1546
Python Site Hooks Creation During Package InstallationTTPNULLSysmon EventID 1 AND Sysmon EventID 11T1546
Registry Keys for Creating SHIM DatabasesTTPNULLSysmon EventID 13T1546.011
Registry Keys Used For Privilege EscalationTTPNULLSysmon EventID 13T1546.012
Screensaver Event Trigger ExecutionTTPNULLSysmon EventID 13T1546.002
Shim Database File CreationTTPNULLSysmon EventID 11T1546.011
Shim Database Installation With Suspicious ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1546.011

Sub-techniques18

IDNameExamples
T1546.001Change Default File Association2
T1546.002Screensaver1
T1546.003Windows Management Instrumentation Event Subscription25
T1546.004Unix Shell Configuration Modification7
T1546.005Trap0
T1546.006LC_LOAD_DYLIB Addition0
T1546.007Netsh Helper DLL1
T1546.008Accessibility Features7
T1546.009AppCert DLLs1
T1546.010AppInit DLLs4
T1546.011Application Shimming4
T1546.012Image File Execution Options Injection3
T1546.013PowerShell Profile1
T1546.014Emond0
T1546.015Component Object Model Hijacking12
T1546.016Installer Packages5
T1546.017Udev Rules1
T1546.018Python Startup Hooks2

Groups0

None recorded.

Software4

Campaigns1

Procedure examples5

Software4

Used byProcedure example
MalwareMini Shai-Hulud

Mini Shai-Hulud has modified settings and configuration files of AI coding agents and other coding applications in order to create event triggered executions through creating hooks and runOn conditions.

ToolPacu

Pacu can set up S3 bucket notifications to trigger a malicious Lambda function when a CloudFormation template is uploaded to the bucket. It can also create Lambda functions that trigger upon the creation of users, roles, and groups.

MalwareUPSTYLE

UPSTYLE creates a `.pth` file beginning with the text `import` so that any time another process or script attempts to reference the modified item the malicious code will also run.

MalwareXCSSET

XCSSET's `dfhsebxzod` module searches for `.xcodeproj` directories within the user’s home folder and subdirectories. For each match, it locates the corresponding `project.pbxproj` file and embeds an encoded payload into a build rule, target configuration, or project setting. The payload is later executed during the build process.

Campaigns1

Used byProcedure example
CampaignKV Botnet Activity

KV Botnet Activity involves managing events on victim systems via libevent to execute a callback function when any running process contains the following references in their path without also having a reference to bioset: busybox, wget, curl, tftp, telnetd, or lua. If the bioset string is not found, the related process is terminated.

References6

  1. Backdooring an AWS account Open source
    Daniel Grzelak. (2016, July 9). Backdooring an AWS account. Retrieved May 27, 2022.
  2. FireEye WMI 2015 Open source
    Ballenthin, W., et al. (2015). Windows Management Instrumentation (WMI) Offense, Defense, and Forensics. Retrieved March 30, 2016.
  3. Malware Persistence on OS X Open source
    Patrick Wardle. (2015). Malware Persistence on OS X Yosemite. Retrieved July 10, 2017.
  4. Microsoft DART Case Report 001 Open source
    Berk Veral. (2020, March 9). Real-life cybercrime stories from DART, the Microsoft Detection and Response Team. Retrieved May 27, 2022.
  5. Varonis Power Automate Data Exfiltration Open source
    Eric Saraga. (2022, February 2). Using Power Automate for Covert Data Exfiltration in Microsoft 365. Retrieved May 27, 2022.
  6. amnesia malware Open source
    Claud Xiao, Cong Zheng, Yanhui Jia. (2017, April 6). New IoT/Linux Malware Targets DVRs, Forms Botnet. Retrieved February 19, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.