T1547 Boot or Logon Autostart Execution
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon.(Citation: Microsoft Run Key)(Citation: MSDN Authentication Packages)(Citation: Microsoft…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Leviathan Registry Key Activitycriticaltest · windows
- Potential Ryuk Ransomware Activityhighstable · windows
- Bypass UAC Using Event Viewerhightest · windows
- Creation Exe for Service with Unquoted Pathhightest · windows
- DLL Load via LSASShightest · windows
- Default RDP Port Changed to Non Standard Porthightest · windows
- File Creation In Suspicious Directory By Msdt.EXEhightest · windows
- Forest Blizzard APT - Custom Protocol Handler Creationhightest · windows
- Forest Blizzard APT - Custom Protocol Handler DLL Registry Sethightest · windows
- Kapeka Backdoor Autorun Persistencehightest · windows
- Loading of Kernel Module via Insmodhightest · linux
- Modify User Shell Folders Startup Valuehightest · windows
- Narrator's Feedback-Hub Persistencehightest · windows
- New TimeProviders Registered With Uncommon DLL Namehightest · windows
- Potential KamiKakaBot Activity - Winlogon Shell Persistencehightest · windows
- Potential RipZip Attack on Startup Folderhightest · windows
- Potential Startup Shortcut Persistence Via PowerShell.EXEhightest · windows
- Registry Persistence Mechanisms in Recycle Binhightest · windows
- Registry Persistence via Explorer Run Keyhightest · windows
- Security Support Provider (SSP) Added to LSA Configurationhightest · windows
- Suspicious GrpConv Executionhightest · windows
- Suspicious Run Key from Downloadhightest · windows
- Suspicious Startup Folder Persistencehightest · windows
- Suspicious VBScript UN2452 Patternhightest · windows
- VBScript Payload Stored in Registryhightest · windows
Mostrando 25 de 62.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.