Cross-source coverage

T1547 / ATT&CK

Boot or Logon Autostart Execution

262 rules · 261 families across 10 sources.

5 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Since some boot or logon autostart programs run with higher privileges, an adversary may leverage these to elevate privileges.

Platforms
Linux · macOS · Windows · Network Devices
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlog

How MITRE says to detect it DET0274

Boot or Logon Autostart Execution Detection Strategy

Windows Analytic 0764

Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=13, 14

Linux Analytic 0765

Correlates creation/modification of systemd service files or /etc/init.d scripts with outlier process behavior during boot

  • auditd:SYSCALL creat
  • auditd:SYSCALL write
  • auditd:SYSCALL Execution of binaries located in /etc/init.d/ or systemd service paths

macOS Analytic 0766

Observes creation or modification of LaunchAgent/LaunchDaemon property list files combined with anomalous plist payload execution after user logon

  • macos:unifiedlog Observed loading of new LaunchAgent or LaunchDaemon plist
  • macos:unifiedlog write
  • macos:unifiedlog Execution of binary listed in newly modified LaunchAgent plist

Sub-techniques with coverage

Counted in the 262 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

63 rules
Detection Severity Format
Leviathan Registry Key Activity Critical Sigma
Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator High Sigma
Bypass UAC Using Event Viewer High Sigma
Creation Exe for Service with Unquoted Path High Sigma
Default RDP Port Changed to Non Standard Port High Sigma
DLL Load via LSASS High Sigma
File Creation In Suspicious Directory By Msdt.EXE High Sigma
Forest Blizzard APT - Custom Protocol Handler Creation High Sigma
Forest Blizzard APT - Custom Protocol Handler DLL Registry Set High Sigma
Kapeka Backdoor Autorun Persistence High Sigma

+ 53 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

49 rules
Detection Severity Format
Attempt to Unload Elastic Endpoint Security Kernel Extension High Elastic TOML
Kernel Module Load from Unusual Location High Elastic TOML
Lateral Movement via Startup Folder High Elastic TOML
Mimikatz Memssp Log File Detected High Elastic TOML
Persistence via a Hidden Plist Filename High Elastic TOML
Persistence via Hidden Run Key Detected High Elastic TOML
Persistence via Suspicious Launch Agent or Launch Daemon High Elastic TOML
Persistence via WMI Standard Registry Provider High Elastic TOML
Potential REMCOS Trojan Execution High Elastic TOML
Suspicious Startup Shell Folder Modification High Elastic TOML

+ 39 more from elastic/detection-rules → showing the 10 highest-severity

elastic/protections-artifacts

42 rules
Detection Severity Format
Dock Tile Plug-In Load Undefined Elastic TOML
Dual Persistence via Startup and Scheduled Task Undefined Elastic TOML
Elastic Endpoint Security Kernel Extension Unload Undefined Elastic TOML
Initial Access or Execution via Microsoft Office Application Undefined Elastic TOML
Initial Access via macOS Installer Package Undefined Elastic TOML
Loadable Kernel Module Loaded via Loader Undefined Elastic TOML
Loadable Kernel Module Loaded via Unusual Parent Undefined Elastic TOML
Loadable Kernel Module Load Followed by Log Clearing Undefined Elastic TOML
Loadable Kernel Module Load via Forked Memory File Descriptor Undefined Elastic TOML
Microsoft Office Process Setting Persistence via Startup Undefined Elastic TOML

+ 32 more from elastic/protections-artifacts → showing the 10 highest-severity

socfortress/Wazuh-Rules

42 rules · 41 families
Detection Severity Format
Detects loading of kernel modules with insmod command. 2 variants High Wazuh XML
Detects loading of kernel modules with insmod command. 2 variants High Wazuh XML
Kernel module loaded from suspicious path (tmp, shm) - T1547.006 High Wazuh XML
Potential malicious kernel module (.ko) being inserted (T1547.006) High Wazuh XML
Powershell script: Persistence mechanism cmdlet detected High Wazuh XML
Sysmon - Event 13: RegistryEvent (Value Set) by · Add Custom Authentication Package DLL (T1547.002) High Wazuh XML
Sysmon - Event 13: RegistryEvent (Value Set) by · LSASS Persistence Cleanup (T1547.008) High Wazuh XML
Sysmon - Event 1: Process creation · .lnk shortcut executed (T1547.009) High Wazuh XML
Sysmon - Event 1: Process creation · LSASS Targeted Process Creation (T1547.008) High Wazuh XML
Sysmon - Event 1: Process creation · Startup Payload Execution (T1547.001) High Wazuh XML

+ 32 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

splunk/security_content

33 rules
Detection Severity Format
Active Setup Registry Autostart Undefined SPL
Linux Auditd Insert Kernel Module Using Insmod Utility Undefined SPL
Linux Auditd Install Kernel Module Using Modprobe Utility Undefined SPL
Linux Auditd Kernel Module Using Rmmod Utility Undefined SPL
Linux Auditd Unload Module Via Modprobe Undefined SPL
Linux File Created In Kernel Driver Directory Undefined SPL
Linux File Creation In System Generator Directory Undefined SPL
Linux Insert Kernel Module Using Insmod Utility Undefined SPL
Linux Install Kernel Module Using Modprobe Utility Undefined SPL
Linux MOTD Script Added Undefined SPL

+ 23 more from splunk/security_content → showing the 10 highest-severity

Wazuh Core Ruleset

11 rules
Detection Severity Format
Powershell process has copied an executable file to Windows start-up folder Critical Wazuh XML
Printer driver failed to load, possible remote code execution using PrinterNightmare exploit: CVE-2021-34527. Critical Wazuh XML
Possible addition of new item to Windows startup registry High Wazuh XML
Registry entry to be executed on next logon points to a remote access tool High Wazuh XML
Signed but untrusted kernel module was loaded High Wazuh XML
Suspicious file extension detected in registry ASEP to be executed on next logon High Wazuh XML
Unsigned kernel module was loaded High Wazuh XML
An executable file has been copied to Windows start-up folder Medium Wazuh XML
Registry entry to be executed on next logon was modified using command line application reg.exe Medium Wazuh XML
osquery: : CCleaner Trojan Floxif detected on registry path · osquery.name = CCleaner_Trojan.Floxif Low Wazuh XML

+ 1 more from Wazuh Core Ruleset → showing the 10 highest-severity

Emerging Threats Open

9 rules
Detection Severity Format
ET HUNTING Powershell ScheduledTasks cmdlet Disable-ScheduledTask command in HTTP Body Response High Suricata
ET HUNTING Powershell ScheduledTasks cmdlet Enable-ScheduledTask command in HTTP Body Response High Suricata
ET HUNTING Powershell ScheduledTasks cmdlet Get-ScheduledTask command in HTTP Body Response High Suricata
ET HUNTING Powershell ScheduledTasks cmdlet New-ScheduledTask command in HTTP Body Response High Suricata
ET HUNTING Powershell ScheduledTasks cmdlet Register-ScheduledTask command in HTTP Body Response High Suricata
ET HUNTING Powershell ScheduledTasks cmdlet Set-ScheduledTask command in HTTP Body Response High Suricata
ET HUNTING Powershell ScheduledTasks cmdlet Start-ScheduledTask command in HTTP Body Response High Suricata
ET HUNTING Powershell ScheduledTasks cmdlet Stop-ScheduledTask command in HTTP Body Response High Suricata
ET HUNTING Powershell ScheduledTasks cmdlet Unregister-ScheduledTask command in HTTP Body Response High Suricata

chronicle/detection-rules

9 rules
Detection Severity Format
default_rdp_port_changed_to_non_standard_port High YARA-L
modify_user_shell_folders_startup_value High YARA-L
new_run_key_pointing_to_suspicious_folder High YARA-L
currentcontrolset_autorun_keys_modification Medium YARA-L
currentversion_autorun_keys_modification Medium YARA-L
direct_autorun_keys_modification Medium YARA-L
potential_suspicious_activity_using_secedit Medium YARA-L
session_manager_autorun_keys_modification Medium YARA-L
suspicious_powershell_in_registry_run_keys Medium YARA-L

Azure/Azure-Sentinel

3 rules
Detection Severity Format
Midnight Blizzard - suspicious rundll32.exe execution of vbscript Medium KQL
Midnight Blizzard - suspicious rundll32.exe execution of vbscript (Normalized Process Events) Medium KQL
List all the VScode Extensions which are installed on a user system Undefined KQL

panther-labs/panther-analysis

1 rule
Detection Severity Format
CrowdStrike MacOS plutil Novel Plist Modification (Anomaly Detection) Medium Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.