Boot or Logon Autostart Execution: XDG Autostart Entries T1547.013
Tactics: Persistence, Privilege Escalation
Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user’s desktop environment is loaded at login. XDG Autostart entries are available for any XDG-compliant Linux system. XDG Autostart entries use Desktop Entry files (`.desktop`) to configure the user’s desktop environment upon user login. These configuration files determine what applications launch upon user login, define associated applications to open specific file types, and define applications used to open removable media.
Authoring guide
These 5 rules share fields, values, and exclusions.
Fields filtered most (11 distinct)
These fields appear most often in rule filters.
Top indicator values (248 distinct)
These values appear most often in rule predicates.
Exclusions (89 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Linux
Domain: Endpoint