Boot or Logon Initialization Scripts: Login Hook T1037.002
Tactics: Persistence, Privilege Escalation
Adversaries may use a Login Hook to establish persistence executed upon user logon. A login hook is a plist file that points to a specific script to execute with root privileges upon user logon. The plist file is located in the /Library/Preferences/com.apple.loginwindow.plist file and can be modified using the defaults command-line utility. This behavior is the same for logout hooks where a script can be executed upon user logout. All hooks require administrator permissions to modify or create hooks.
Authoring guide
These 3 rules share fields, values, and exclusions.
Fields filtered most (7 distinct)
These fields appear most often in rule filters.
Top indicator values (11 distinct)
These values appear most often in rule predicates.
Exclusions (18 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: macOS
Domain: Endpoint