{"id":"T1037.001","name":"Logon Script (Windows)","url":"https://attack.mitre.org/techniques/T1037/001","tactics":["persistence","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0072","stix_id":"x-mitre-detection-strategy--3f27e858-2912-4b43-ac03-f668ef30c47e","name":"Detect Logon Script Modifications and Execution","url":"https://attack.mitre.org/detectionstrategies/DET0072","analytics":[{"id":"AN0199","stix_id":"x-mitre-analytic--6dae9309-90a7-4b4e-b764-9486a7ba4390","name":"Analytic 0199","description":"Detects adversary use of logon script configuration via Group Policy or user object attributes, followed by script execution post-authentication. Behavior includes modification of script path or file, then process execution under user logon context.","url":"https://attack.mitre.org/detectionstrategies/DET0072#AN0199","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:System","channel":"EventCode=1502, 1503","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"script_path_keywords","description":"Defenders may tune for known script locations such as NETLOGON, SYSVOL, or \\domain\\sysvol\\*.bat/.ps1"},{"field":"execution_time_window","description":"May be scoped to user logon hours or first X minutes post-authentication"},{"field":"user_context","description":"Organizations may focus on specific users/groups with high privilege or remote access"}],"live":true,"detection_strategies":["DET0072"],"techniques":["T1037.001"]}],"live":true,"version":"1.0","techniques":["T1037.001"]}],"sigma_rules":[{"id":"0a98a10c-685d-4ab0-bddc-b6bdd1d48458","title":"Uncommon Userinit Child Process","author":"Tom Ueltschi (@c_APT_ure), Tim Shelton","status":"test","level":"high","date":"2019-01-12","modified":"2023-11-14","description":"Detects uncommon \"userinit.exe\" child processes, which could be a sign of uncommon shells or login scripts used for persistence.","references":["https://cocomelonc.github.io/persistence/2022/12/09/malware-pers-20.html","https://learn.microsoft.com/en-us/windows-server/administration/server-core/server-core-sconfig#powershell-is-the-default-shell-on-server-core"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.t1037.001","attack.persistence"],"path":"rules/windows/process_creation/proc_creation_win_userinit_uncommon_child_processes.yml","techniques":["T1037.001"],"cves":[]},{"id":"21d856f9-9281-4ded-9377-51a1a6e2a432","title":"Potential Persistence Via Logon Scripts - CommandLine","author":"Tom Ueltschi (@c_APT_ure)","status":"test","level":"high","date":"2019-01-12","modified":"2023-06-09","description":"Detects the addition of a new LogonScript to the registry value \"UserInitMprLogonScript\" for potential persistence","references":["https://cocomelonc.github.io/persistence/2022/12/09/malware-pers-20.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1037.001"],"path":"rules/windows/process_creation/proc_creation_win_registry_logon_script.yml","techniques":["T1037.001"],"cves":[]},{"id":"9ace0707-b560-49b8-b6ca-5148b42f39fb","title":"Potential Persistence Via Logon Scripts - Registry","author":"Tom Ueltschi (@c_APT_ure)","status":"test","level":"medium","date":"2019-01-12","modified":"2025-10-26","description":"Detects creation of \"UserInitMprLogonScript\" registry value which can be used as a persistence method by malicious actors","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1037.001/T1037.001.md"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.privilege-escalation","attack.t1037.001","attack.persistence","attack.lateral-movement"],"path":"rules/windows/registry/registry_set/registry_set_persistence_logon_scripts_userinitmprlogonscript.yml","techniques":["T1037.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}