Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Privilege Escalation, Persistence

T1546.016 Installer Packages

Sub-technique of T1546 Event Triggered Execution

Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content. Installer packages are OS specific and contain the resources an operating system needs to install applications on a system. Installer packages can include scripts that run prior to installation as well as after installation is complete. Installer scripts may inherit…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

SigmaHQ has no rules for this technique.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.