// MITRE ATT&CK

T1546.016 · Installer Packages

🎯 Privilege Escalation LinuxmacOSWindows Sub-technique

Sub-technique of T1546 · Event Triggered Execution.

Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content. Installer packages are OS specific and contain the resources an operating system needs to install applications on a system. Installer packages can include scripts that ru...

How to detect & mitigate it

Detecting Installer Packages starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.