{"id":"T1037.005","name":"Startup Items","url":"https://attack.mitre.org/techniques/T1037/005","tactics":["persistence","privilege-escalation"],"platforms":["macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0429","stix_id":"x-mitre-detection-strategy--7eb6ccf9-8fb5-4c7d-8a2c-33081c3ddf81","name":"Detect Modification of macOS Startup Items","url":"https://attack.mitre.org/detectionstrategies/DET0429","analytics":[{"id":"AN1197","stix_id":"x-mitre-analytic--c46d9fac-eac9-479e-91d3-4f5a1066972d","name":"Analytic 1197","description":"Detects the modification or addition of Launch Agents or Startup Items to establish persistence. Adversaries may write plist or executable files to ~/Library/LaunchAgents/, /Library/StartupItems/, or similar directories and configure them to run at user or system boot. Detection requires correlating file creation or modification events with subsequent user logon or boot-time process execution.","url":"https://attack.mitre.org/detectionstrategies/DET0429#AN1197","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"launchservices or loginwindow events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:fsevents","channel":"/Library/StartupItems/, ~/Library/LaunchAgents/","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-fsevents"}],"mutable_elements":[{"field":"directory_path","description":"Specific paths to monitor may differ across macOS versions or enterprise baselines."},{"field":"user_context","description":"Different users may have unique LaunchAgents folders—tuning may be required."},{"field":"time_window","description":"The correlation time between file creation and process execution may need to be adjusted for boot persistence."},{"field":"process_name","description":"Specific startup binaries (e.g., bash, osascript) may vary across implementations."}],"live":true,"detection_strategies":["DET0429"],"techniques":["T1037.005"]}],"live":true,"version":"1.0","techniques":["T1037.005"]}],"sigma_rules":[{"id":"dfe8b941-4e54-4242-b674-6b613d521962","title":"Startup Item File Created - MacOS","author":"Alejandro Ortuno, oscd.community","status":"test","level":"low","date":"2020-10-14","modified":"2024-08-11","description":"Detects the creation of a startup item plist file, that automatically get executed at boot initialization to establish persistence.\nAdversaries may use startup items automatically executed at boot initialization to establish persistence.\nStartup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1037.005/T1037.005.md","https://developer.apple.com/library/archive/documentation/MacOSX/Conceptual/BPSystemStartup/Chapters/StartupItems.html"],"logsource":{"product":"macos","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1037.005"],"path":"rules/macos/file_event/file_event_macos_susp_startup_item_created.yml","techniques":["T1037.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}