Boot or Logon Initialization Scripts: Startup Items T1037.005
Tactics: Persistence, Privilege Escalation
Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | create | File or Directory Create |
| Sysmon-for-Linux | Event ID 11 | File created |
Authoring guide
These 3 rules share fields, values, and exclusions.
Fields filtered most (5 distinct)
These fields appear most often in rule filters.
Top indicator values (10 distinct)
These values appear most often in rule predicates.
Exclusions (2 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Domain: Endpoint