{"id":"T1037.004","name":"RC Scripts","url":"https://attack.mitre.org/techniques/T1037/004","tactics":["persistence","privilege-escalation"],"platforms":["macOS","Linux","Network Devices","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0237","stix_id":"x-mitre-detection-strategy--be6a466c-40c6-4611-9b68-7cfcbcb35fb0","name":"Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts","url":"https://attack.mitre.org/detectionstrategies/DET0237","analytics":[{"id":"AN0658","stix_id":"x-mitre-analytic--98f8728d-ff74-47cb-b884-25071a21f77e","name":"Analytic 0658","description":"Detection of modified or newly created /etc/rc.local or /etc/init.d scripts followed by suspicious execution during system startup.","url":"https://attack.mitre.org/detectionstrategies/DET0237#AN0658","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"boot logs","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"script_path","description":"Specific path of init script (e.g., /etc/rc.local, /etc/init.d/*) may vary by distribution"},{"field":"user_context","description":"Root vs. non-root modification context depending on configuration"},{"field":"time_window","description":"Tuning window for script creation or modification relative to system boot"}],"live":true,"detection_strategies":["DET0237"],"techniques":["T1037.004"]},{"id":"AN0659","stix_id":"x-mitre-analytic--e716b209-5b06-4bc4-843f-cbe4c51ddc0d","name":"Analytic 0659","description":"Detection of edits or additions to /etc/rc.common, /Library/StartupItems, or /System/Library/StartupItems and associated script execution during login or reboot.","url":"https://attack.mitre.org/detectionstrategies/DET0237#AN0659","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"file activity","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"script_name","description":"Name of script or LaunchDaemon plist is tunable across environments"},{"field":"event_interval","description":"Time window between modification and reboot/login"},{"field":"file_permission","description":"Permissions on modified RC files can vary between systems"}],"live":true,"detection_strategies":["DET0237"],"techniques":["T1037.004"]},{"id":"AN0660","stix_id":"x-mitre-analytic--69562961-14e6-42a7-9f8a-24ac00f6404e","name":"Analytic 0660","description":"Detection of changes to /etc/rc.local.d/local.sh or rc.local during post-boot script execution with abnormal commands or additions.","url":"https://attack.mitre.org/detectionstrategies/DET0237#AN0660","platforms":["ESXi"],"log_source_references":[{"name":"esxi:syslog","channel":"boot logs","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-syslog"},{"name":"esxi:shell","channel":"admin command usage","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"esxi-shell"}],"mutable_elements":[{"field":"script_section","description":"Tunable script section edited by adversary (beginning, end, inline)"},{"field":"command_type","description":"Nature of embedded command or payload affects detection scope"},{"field":"execution_trigger","description":"Boot vs. manual script re-invocation"}],"live":true,"detection_strategies":["DET0237"],"techniques":["T1037.004"]},{"id":"AN0661","stix_id":"x-mitre-analytic--b053dbd4-ad1e-45e1-a6b7-af2a5d931c82","name":"Analytic 0661","description":"Detection of modified boot-time configuration scripts that persist malicious CLI commands across reboots.","url":"https://attack.mitre.org/detectionstrategies/DET0237#AN0661","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"startup-config","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"networkdevice-syslog"},{"name":"networkdevice:syslog","channel":"system boot logs","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"firmware_family","description":"Device type or OS determines specific init script location"},{"field":"config_line_pattern","description":"Regex or pattern matching approach to detect suspicious CLI"},{"field":"reboot_time_window","description":"Time window between config change and first boot post-modification"}],"live":true,"detection_strategies":["DET0237"],"techniques":["T1037.004"]}],"live":true,"version":"1.0","techniques":["T1037.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}