Boot or Logon Initialization Scripts: RC Scripts T1037.004
Tactics: Persistence, Privilege Escalation
Adversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system’s startup. These files allow system administrators to map and start custom services at startup for different run levels. RC scripts require root privileges to modify.
Events covered
5 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
| ESF | open | File Open |
| ESF | create | File or Directory Create |
| ESF | write | File Write |
| Sysmon-for-Linux | Event ID 11 | File created |
Authoring guide
These 12 rules share fields, values, and exclusions.
Fields filtered most (17 distinct)
These fields appear most often in rule filters.
Top indicator values (430 distinct)
These values appear most often in rule predicates.
Exclusions (187 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Domain: Endpoint
Elastic 11 rules
- Executable Bit Set for Potential Persistence Script
- GenAI Process Accessing Sensitive Files
- Persistence via GenAI Tool
- Pod or Container Creation with Suspicious Command-Line
- Potential Execution of rc.local Script
- Potential Persistence via File Modification
- Potential Suspicious File Edit
- rc.local/rc.common File Creation
- Suspicious Network Activity to the Internet by Previously Unknown Executable
- Suspicious rc.local Error Message
- System V Init Script Created