Boot or Logon Initialization Scripts: Startup Items T1037.005

Tactics: Persistence, Privilege Escalation

Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items.

Events covered

2 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 3 rules share fields, values, and exclusions.

Fields filtered most (5 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
TargetFilename3contains 1, ends_with 1, starts_with 1, wildcard 1.plist, /lib/systemd/system-generators/, /library/startupitems/, /library/startupitems/*/startupparameters.plist, /system/library/startupitems
event.type1ne 1deletion
event_action1in 1created, modified
file.name1eq 1StartupParameters.plist
host.os.type1eq 1

Top indicator values (10 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
TargetFilenamecontains
/lib/systemd/system-generators/
1
TargetFilenameends_with
.plist
13
TargetFilenamestarts_with
/library/startupitems/
1
TargetFilenamestarts_with
/system/library/startupitems
1
TargetFilenamewildcard
/library/startupitems/*/startupparameters.plist
1
TargetFilenamewildcard
/system/library/startupitems/*/startupparameters.plist
1
event.typene
deletion
132
event_actionin
created
18
event_actionin
modified
18
file.nameeq
StartupParameters.plist
1

Exclusions (2 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.signing_ideq
com.apple.shove
1
process.code_signature.trustedeq
true
1

Rules under this technique

These vendors publish rules tagged with this technique.

Domain: Endpoint

Platform (all)

Sigma 1 rule

Elastic 1 rule

Splunk 1 rule