// MITRE ATT&CK

T1037.005 · Startup Items

🎯 Persistence macOS Sub-technique

Sub-technique of T1037 · Boot or Logon Initialization Scripts.

Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the exec...

How to detect & mitigate it

Detecting Startup Items starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.