Boot or Logon Initialization Scripts: RC Scripts T1037.004

Tactics: Persistence, Privilege Escalation

Adversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system’s startup. These files allow system administrators to map and start custom services at startup for different run levels. RC scripts require root privileges to modify.

Events covered

5 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 12 rules share fields, values, and exclusions.

Fields filtered most (17 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType10in 7, eq 3creation, exec, exec_event, file_create_event, start
host.os.type9eq 9
TargetFilename6wildcard 3, in 2, starts_with 1/etc/rc.local, */etc/init.d/*, */etc/rc.d/*, */etc/rc.local*, /boot/efi/efi/*/grub.cfg
process_name5eq 3, in 2, is_not_null 1chmod, claude, claude.exe, codex, ctl
event.type4eq 4start, info
data_stream.dataset2eq 2fim.event, system.syslog
process.args2eq 1, in 1, starts_with 1, wildcard 1+x, --, --restart=Never, -m, /etc/NetworkManager/dispatcher.d/*
CommandLine1wildcard 1* nc *, * nc.traditional *, * ncat *
Image1eq 1, starts_with 1, wildcard 1./, /boot/, /dev/shm/
event.category1eq 1network
event.outcome1eq 1success
event_action1eq 1created
file.extension1eq 1swp
file.name1eq 1, in 1.bash_logout, .bash_profile, .bashrc
message1in 1command not found, connection refused, no such file or directory

Top indicator values (430 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypein
creation
334
EventTypein
exec
3206
EventTypein
start
3168
EventTypein
exec_event
2150
EventTypein
file_create_event
29
event.typeeq
start
31087
TargetFilenamewildcard
/etc/rc.local
22
TargetFilenamewildcard
/etc/sudoers
22
CommandLinewildcard
* nc *
17
CommandLinewildcard
* nc.traditional *
1
CommandLinewildcard
* ncat *
12
CommandLinewildcard
* netcat *
12
CommandLinewildcard
*./.*
12
CommandLinewildcard
*/boot/*
1
CommandLinewildcard
*/dev/shm/*
19
CommandLinewildcard
*/dev/tcp/*
15
CommandLinewildcard
*/etc/init.d*
14
CommandLinewildcard
*/etc/ld.so*
14
CommandLinewildcard
*/etc/profile*
13
CommandLinewildcard
*/etc/rc.local*
14
CommandLinewildcard
*/etc/shadow*
112
CommandLinewildcard
*/etc/ssh*
110
CommandLinewildcard
*/etc/sudoers*
14
CommandLinewildcard
*/etc/update-motd.d*
14
CommandLinewildcard
*/home/*/.ssh/*
111
CommandLinewildcard
*/lost+found/*
1
CommandLinewildcard
*/media/*
1
CommandLinewildcard
*/proc/*
1
CommandLinewildcard
*/root/.ssh*
19
CommandLinewildcard
*/sys/*
1

Exclusions (187 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
file.extensionin
dpkg-remove
3
Imagein
/bin/autossl_check
2
Imagein
/bin/chef-client
2
Imagein
/bin/dnf
2
Imagein
/bin/dnf-automatic
2
Imagein
/bin/dockerd
2
Imagein
/bin/dpkg
2
Imagein
/bin/dpkg-divert
2
Imagein
/bin/microdnf
2
Imagein
/bin/pacman
2
Imagein
/bin/pamac-daemon
2
Imagein
/bin/podman
2
Imagein
/bin/puppet
2
Imagein
/bin/rpm
2
Imagein
/bin/snapd
2

Rules under this technique

These vendors publish rules tagged with this technique.

Domain: Endpoint

Platform (all)

Elastic 11 rules

Splunk 1 rule