Techniques › T1547
T1547 Boot or Logon Autostart Execution
persistence · privilege escalation — Linux, macOS, Windows, Network Devices · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
7
Sigma rules tagged attack.t1547
1
KEV CVEs mapped here
<p>Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.</p><p>Since some boot or logon autostart programs run with higher privileges, an adversary may leverage these to elevate privileges.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2023-2533 | PaperCut NG/MF | primary impact | Mapped | 2025-07-28 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0274 Boot or Logon Autostart Execution Detection Strategy v1.0
AN0764 WindowsCorrelation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startupTunable:
ParentProcessNameStartupRegistryPathAN0765 LinuxCorrelates creation/modification of systemd service files or /etc/init.d scripts with outlier process behavior during bootauditd:SYSCALLExecution of binaries located in /etc/init.d/ or systemd service paths→ DC0032 Process CreationTunable:FilePathUserContextAN0766 macOSObserves creation or modification of LaunchAgent/LaunchDaemon property list files combined with anomalous plist payload execution after user logonmacos:unifiedlogObserved loading of new LaunchAgent or LaunchDaemon plist→ DC0041 Service Metadatamacos:unifiedlogExecution of binary listed in newly modified LaunchAgent plist→ DC0032 Process CreationTunable:PlistKeyTimeWindow
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1547
Author: Elastic, Josh Nickels, Marius Rothenbücher
· 2024-09-06 · logsource: product=windows service=security · 123e4e6d-b123-48f8-b261-7214938acaf0
Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.
Author: frack113
· 2021-11-18 (modified 2022-12-06) · logsource: product=windows category=registry_event · 277efb8f-60be-4f10-b4d3-037802f37167
Detects persistence registry keys for Recycle Bin
Author: Mateusz Wydra, oscd.community
· 2020-10-13 (modified 2023-01-19) · logsource: product=windows category=registry_event · 9577edbb-851f-4243-8c91-1d5b50c1a39b
Detects creation/modification of Assistive Technology applications and persistence with usage of 'at'
Author: Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger
· 2021-09-30 (modified 2022-10-09) · logsource: product=windows category=process_creation · a2ea3ae7-d3d0-40a0-a55c-25a45c87cac1
Detects when a possible suspicious driver is being installed via pnputil.exe lolbin
Author: Greg (rule)
· 2022-07-21 (modified 2023-01-05) · logsource: product=windows category=file_event · a6976974-ea6f-4e97-818e-ea08625c52cb
Detects a phishing attack which expands a ZIP file containing a malicious shortcut.
If the victim expands the ZIP file via the explorer process, then the explorer process expands the malicious ZIP file and drops a malicious shortcut redirected to a backdoor into the Startup folder.
Additionally, the file name of the malicious shortcut in Startup folder contains {0AFACED1-E828-11D1-9187-B532F1E9575D} meaning the folder shortcut operation.
Author: omkar72
· 2020-10-30 (modified 2021-11-27) · logsource: product=windows category=registry_event · b98968aa-dbc0-4a9c-ac35-108363cbf8d5
Detects potential malicious modification of run keys by winekey or team9 backdoor
Author: Florian Roth (Nextron Systems)
· 2022-05-19 · logsource: product=windows category=process_creation · f14e169e-9978-4c69-acb3-1cff8200bc36
Detects the suspicious execution of a utility to convert Windows 3.x .grp files or for persistence purposes by malicious software or actors
Sub-techniques
| ID | Name | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1547.001 | Registry Run Keys / Startup Folder | 39 | 1 |
| T1547.002 | Authentication Package | 1 | 0 |
| T1547.003 | Time Providers | 1 | 0 |
| T1547.004 | Winlogon Helper DLL | 4 | 0 |
| T1547.005 | Security Support Provider | 1 | 0 |
| T1547.006 | Kernel Modules and Extensions | 2 | 0 |
| T1547.007 | Re-opened Applications | 0 | 0 |
| T1547.008 | LSASS Driver | 1 | 0 |
| T1547.009 | Shortcut Modification | 4 | 1 |
| T1547.010 | Port Monitors | 4 | 0 |
| T1547.012 | Print Processors | 0 | 0 |
| T1547.013 | XDG Autostart Entries | 0 | 0 |
| T1547.014 | Active Setup | 1 | 0 |
| T1547.015 | Login Items | 1 | 0 |