Cross-source coverage
T1547 / ATT&CK
Boot or Logon Autostart Execution
267 rules · 266 families across 10 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.
Since some boot or logon autostart programs run with higher privileges, an adversary may leverage these to elevate privileges.
- Tactics
- Persistence · Privilege Escalation
- Platforms
- Linux · macOS · Windows · Network Devices
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlog
How MITRE says to detect it DET0274
Boot or Logon Autostart Execution Detection Strategy
Windows Analytic 0764
Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=13, 14
Linux Analytic 0765
Correlates creation/modification of systemd service files or /etc/init.d scripts with outlier process behavior during boot
auditd:SYSCALLcreatauditd:SYSCALLwriteauditd:SYSCALLExecution of binaries located in /etc/init.d/ or systemd service paths
macOS Analytic 0766
Observes creation or modification of LaunchAgent/LaunchDaemon property list files combined with anomalous plist payload execution after user logon
macos:unifiedlogObserved loading of new LaunchAgent or LaunchDaemon plistmacos:unifiedlogwritemacos:unifiedlogExecution of binary listed in newly modified LaunchAgent plist
Sub-techniques with coverage
Counted in the 267 above — a rule tagged a sub-technique covers this technique too.
- T1547.001 Registry Run Keys / Startup Folder 103
- T1547.006 Kernel Modules and Extensions 42
- T1547.012 Print Processors 11
- T1547.009 Shortcut Modification 8
- T1547.005 Security Support Provider 7
- T1547.010 Port Monitors 7
- T1547.004 Winlogon Helper DLL 5
- T1547.013 XDG Autostart Entries 5
- T1547.014 Active Setup 5
- T1547.002 Authentication Package 4
- T1547.003 Time Providers 3
- T1547.008 LSASS Driver 3
- T1547.011 Plist Modification 3
- T1547.015 Login Items 2
SigmaHQ/sigma
63 rules| Detection | Severity | Format |
|---|---|---|
| Leviathan Registry Key Activity | Critical | Sigma |
| Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator | High | Sigma |
| Bypass UAC Using Event Viewer | High | Sigma |
| Creation Exe for Service with Unquoted Path | High | Sigma |
| Default RDP Port Changed to Non Standard Port | High | Sigma |
| DLL Load via LSASS | High | Sigma |
| File Creation In Suspicious Directory By Msdt.EXE | High | Sigma |
| Forest Blizzard APT - Custom Protocol Handler Creation | High | Sigma |
| Forest Blizzard APT - Custom Protocol Handler DLL Registry Set | High | Sigma |
| Kapeka Backdoor Autorun Persistence | High | Sigma |
+ 53 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
51 rules| Detection | Severity | Format |
|---|---|---|
| Attempt to Unload Elastic Endpoint Security Kernel Extension | High | Elastic TOML |
| Kernel Module Load from Unusual Location | High | Elastic TOML |
| Lateral Movement via Startup Folder | High | Elastic TOML |
| Mimikatz Memssp Log File Detected | High | Elastic TOML |
| Persistence via a Hidden Plist Filename | High | Elastic TOML |
| Persistence via Hidden Run Key Detected | High | Elastic TOML |
| Persistence via Suspicious Launch Agent or Launch Daemon | High | Elastic TOML |
| Persistence via WMI Standard Registry Provider | High | Elastic TOML |
| Potential REMCOS Trojan Execution | High | Elastic TOML |
| Suspicious Startup Shell Folder Modification | High | Elastic TOML |
+ 41 more from elastic/detection-rules → showing the 10 highest-severity
elastic/protections-artifacts
42 rules| Detection | Severity | Format |
|---|---|---|
| Dock Tile Plug-In Load | Undefined | Elastic TOML |
| Dual Persistence via Startup and Scheduled Task | Undefined | Elastic TOML |
| Elastic Endpoint Security Kernel Extension Unload | Undefined | Elastic TOML |
| Initial Access or Execution via Microsoft Office Application | Undefined | Elastic TOML |
| Initial Access via macOS Installer Package | Undefined | Elastic TOML |
| Loadable Kernel Module Loaded via Loader | Undefined | Elastic TOML |
| Loadable Kernel Module Loaded via Unusual Parent | Undefined | Elastic TOML |
| Loadable Kernel Module Load Followed by Log Clearing | Undefined | Elastic TOML |
| Loadable Kernel Module Load via Forked Memory File Descriptor | Undefined | Elastic TOML |
| Microsoft Office Process Setting Persistence via Startup | Undefined | Elastic TOML |
+ 32 more from elastic/protections-artifacts → showing the 10 highest-severity
socfortress/Wazuh-Rules
42 rules · 41 families| Detection | Severity | Format |
|---|---|---|
| Detects loading of kernel modules with insmod command. 2 variants | High | Wazuh XML |
| Detects loading of kernel modules with insmod command. 2 variants | High | Wazuh XML |
| Kernel module loaded from suspicious path (tmp, shm) - T1547.006 | High | Wazuh XML |
| Potential malicious kernel module (.ko) being inserted (T1547.006) | High | Wazuh XML |
| Powershell script: Persistence mechanism cmdlet detected | High | Wazuh XML |
| Sysmon - Event 13: RegistryEvent (Value Set) by · Add Custom Authentication Package DLL (T1547.002) | High | Wazuh XML |
| Sysmon - Event 13: RegistryEvent (Value Set) by · LSASS Persistence Cleanup (T1547.008) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · .lnk shortcut executed (T1547.009) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · LSASS Targeted Process Creation (T1547.008) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Startup Payload Execution (T1547.001) | High | Wazuh XML |
+ 32 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
splunk/security_content
33 rules| Detection | Severity | Format |
|---|---|---|
| Active Setup Registry Autostart | Undefined | SPL |
| Linux Auditd Insert Kernel Module Using Insmod Utility | Undefined | SPL |
| Linux Auditd Install Kernel Module Using Modprobe Utility | Undefined | SPL |
| Linux Auditd Kernel Module Using Rmmod Utility | Undefined | SPL |
| Linux Auditd Unload Module Via Modprobe | Undefined | SPL |
| Linux File Created In Kernel Driver Directory | Undefined | SPL |
| Linux File Creation In System Generator Directory | Undefined | SPL |
| Linux Insert Kernel Module Using Insmod Utility | Undefined | SPL |
| Linux Install Kernel Module Using Modprobe Utility | Undefined | SPL |
| Linux MOTD Script Added | Undefined | SPL |
+ 23 more from splunk/security_content → showing the 10 highest-severity
chronicle/detection-rules
12 rules| Detection | Severity | Format |
|---|---|---|
| default_rdp_port_changed_to_non_standard_port | High | YARA-L |
| modify_user_shell_folders_startup_value | High | YARA-L |
| new_run_key_pointing_to_suspicious_folder | High | YARA-L |
| currentcontrolset_autorun_keys_modification | Medium | YARA-L |
| currentversion_autorun_keys_modification | Medium | YARA-L |
| direct_autorun_keys_modification | Medium | YARA-L |
| potential_suspicious_activity_using_secedit | Medium | YARA-L |
| session_manager_autorun_keys_modification | Medium | YARA-L |
| suspicious_powershell_in_registry_run_keys | Medium | YARA-L |
| malicious_behaviour_on_user_login_microsoft_windows__c0d0s0_group_behavior | Undefined | YARA-L |
+ 2 more from chronicle/detection-rules → showing the 10 highest-severity
Wazuh Core Ruleset
11 rules| Detection | Severity | Format |
|---|---|---|
| Powershell process has copied an executable file to Windows start-up folder | Critical | Wazuh XML |
| Printer driver failed to load, possible remote code execution using PrinterNightmare exploit: CVE-2021-34527. | Critical | Wazuh XML |
| Possible addition of new item to Windows startup registry | High | Wazuh XML |
| Registry entry to be executed on next logon points to a remote access tool | High | Wazuh XML |
| Signed but untrusted kernel module was loaded | High | Wazuh XML |
| Suspicious file extension detected in registry ASEP to be executed on next logon | High | Wazuh XML |
| Unsigned kernel module was loaded | High | Wazuh XML |
| An executable file has been copied to Windows start-up folder | Medium | Wazuh XML |
| Registry entry to be executed on next logon was modified using command line application reg.exe | Medium | Wazuh XML |
| osquery: : CCleaner Trojan Floxif detected on registry path · osquery.name = CCleaner_Trojan.Floxif | Low | Wazuh XML |
+ 1 more from Wazuh Core Ruleset → showing the 10 highest-severity
Emerging Threats Open
9 rulesAzure/Azure-Sentinel
3 rules| Detection | Severity | Format |
|---|---|---|
| Midnight Blizzard - suspicious rundll32.exe execution of vbscript | Medium | KQL |
| Midnight Blizzard - suspicious rundll32.exe execution of vbscript (Normalized Process Events) | Medium | KQL |
| List all the VScode Extensions which are installed on a user system | Undefined | KQL |
panther-labs/panther-analysis
1 rule| Detection | Severity | Format |
|---|---|---|
| CrowdStrike MacOS plutil Novel Plist Modification (Anomaly Detection) | Medium | Panther Python |