// MITRE ATT&CK
T1037 · Boot or Logon Initialization Scripts
Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence.(Citation: Mandiant APT29 Eye Spy Email Nov 22)(Citation: Anomali Rocke March 2019) Initialization scripts can be used to perform administrative functions, which may often execute other progra...
How to detect & mitigate it
Detecting Boot or Logon Initialization Scripts starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (5)
T1037.001
Logon Script (Windows) T1037.002
Login Hook T1037.003
Network Logon Script T1037.004
RC Scripts T1037.005
Startup Items
Logon Script (Windows) T1037.002
Login Hook T1037.003
Network Logon Script T1037.004
RC Scripts T1037.005
Startup Items
Related techniques
T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1137
Office Application Startup T1098.003
Additional Cloud Roles
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1137
Office Application Startup T1098.003
Additional Cloud Roles
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.