Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Persistence, Privilege Escalation

T1546.018 Python Startup Hooks

Sub-technique of T1546 Event Triggered Execution

Adversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (`.pth`) files and the `sitecustomize.py` or `usercustomize.py` modules. These files are automatically processed during the initialization of the Python interpreter, allowing for the execution of arbitrary code whenever Python is invoked.(Citation: Volexity GlobalProtect CVE 2024) Path…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

SigmaHQ has no rules for this technique.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.