Boot or Logon Autostart Execution

T1547

Technique with 14 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Since some boot or logon autostart programs run with higher privileges, an adversary may leverage these to elevate privileges.

Detection rules86

Rules on DetectionCode tagged with T1547 or one of its sub-techniques.

Sigma53

RuleLevelLog sourceTechnique
Bypass UAC Using Event Viewerhighwindows / registry_setT1547.010
Creation Exe for Service with Unquoted Pathhighwindows / file_eventT1547.009
Default RDP Port Changed to Non Standard Porthighwindows / registry_setT1547.010
DLL Load via LSASShighwindows / registry_eventT1547.008
File Creation In Suspicious Directory By Msdt.EXEhighwindows / file_eventT1547.001
Loading of Kernel Module via Insmodhighlinux / NULLT1547.006
Modify User Shell Folders Startup Valuehighwindows / registry_setT1547.001
Narrator's Feedback-Hub Persistencehighwindows / registry_eventT1547.001
New RUN Key Pointing to Suspicious Folderhighwindows / registry_setT1547.001
New TimeProviders Registered With Uncommon DLL Namehighwindows / registry_setT1547.003
Potential RipZip Attack on Startup Folderhighwindows / file_eventT1547
Potential Startup Shortcut Persistence Via PowerShell.EXEhighwindows / file_eventT1547.001
Registry Persistence Mechanisms in Recycle Binhighwindows / registry_eventT1547
Registry Persistence via Explorer Run Keyhighwindows / registry_setT1547.001
Security Support Provider (SSP) Added to LSA Configurationhighwindows / registry_eventT1547.005

Splunk33

RuleTypeRiskData sourceTechnique
Active Setup Registry AutostartTTPNULLSysmon EventID 13T1547.014
Linux Auditd Insert Kernel Module Using Insmod UtilityAnomalyNULLLinux Auditd SyscallT1547.006
Linux Auditd Install Kernel Module Using Modprobe UtilityAnomalyNULLLinux Auditd SyscallT1547.006
Linux Auditd Kernel Module Using Rmmod UtilityTTPNULLLinux Auditd SyscallT1547.006
Linux Auditd Unload Module Via ModprobeTTPNULLLinux Auditd ExecveT1547.006
Linux File Created In Kernel Driver DirectoryAnomalyNULLSysmon for Linux EventID 11T1547.006
Linux File Creation In System Generator DirectoryAnomalyNULLSysmon for Linux EventID 11T1547
Linux Insert Kernel Module Using Insmod UtilityAnomalyNULLSysmon for Linux EventID 1T1547.006
Linux Install Kernel Module Using Modprobe UtilityAnomalyNULLSysmon for Linux EventID 1T1547.006
Linux MOTD Script AddedAnomalyNULLSysmon for Linux EventID 11T1547
Linux Suspicious XDG AutostartAnomalyNULLSysmon for Linux EventID 11T1547
Linux UDEV Rule CreatedAnomalyNULLSysmon for Linux EventID 11T1547
Monitor Registry Keys for Print MonitorsTTPNULLSysmon EventID 13T1547.010
Print Processor Registry AutostartTTPNULLSysmon EventID 13T1547.012
Print Spooler Adding A Printer DriverTTPNULLWindows Event Log Printservice 316T1547.012

Sub-techniques14

IDNameExamples
T1547.001Registry Run Keys / Startup Folder261
T1547.002Authentication Package1
T1547.003Time Providers0
T1547.004Winlogon Helper DLL13
T1547.005Security Support Provider3
T1547.006Kernel Modules and Extensions4
T1547.007Re-opened Applications0
T1547.008LSASS Driver2
T1547.009Shortcut Modification29
T1547.010Port Monitors0
T1547.012Print Processors3
T1547.013XDG Autostart Entries7
T1547.014Active Setup1
T1547.015Login Items3

Groups1

Software5

Campaigns0

None recorded.

Procedure examples6

Groups1

Used byProcedure example
GroupAPT42

APT42 has modified the Registry to maintain persistence.

Software5

Used byProcedure example
MalwareBoxCaon

BoxCaon established persistence by setting the HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load registry key to point to its executable.

MalwareDtrack

Dtrack’s RAT makes a persistent target file with auto execution on the host start.

MalwareMis-Type

Mis-Type has created registry keys for persistence, including `HKCU\Software\bkfouerioyou`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6afa8072-b2b1-31a8-b5c1-{Unique Identifier}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3BF41072-B2B1-31A8-B5C1-{Unique Identifier}`.

MalwareMisdat

Misdat has created registry keys for persistence, including `HKCU\Software\dnimtsoleht\StubPath`, `HKCU\Software\snimtsOleht\StubPath`, `HKCU\Software\Backtsaleht\StubPath`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed. Components\{3bf41072-b2b1-21c8-b5c1-bd56d32fbda7}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3ef41072-a2f1-21c8-c5c1-70c2c3bc7905}`.

MalwarexCaon

xCaon has added persistence via the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load which causes the malware to run each time any user logs in.

References5

  1. Cylance Reg Persistence Sept 2013 Open source
    Langendorf, S. (2013, September 24). Windows Registry Persistence, Part 2: The Run Keys and Search-Order. Retrieved November 17, 2024.
  2. Linux Kernel Programming Open source
    Pomerantz, O., Salzman, P.. (2003, April 4). The Linux Kernel Module Programming Guide. Retrieved April 6, 2018.
  3. MSDN Authentication Packages Open source
    Microsoft. (n.d.). Authentication Packages. Retrieved March 1, 2017.
  4. Microsoft Run Key Open source
    Microsoft. (n.d.). Run and RunOnce Registry Keys. Retrieved September 12, 2024.
  5. Microsoft TimeProvider Open source
    Microsoft. (n.d.). Time Provider. Retrieved March 26, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.